CVE-2009-0827
PollHelper - Unauthenticated Arbitrary File Download via Direct Request
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-0827. PoCs published by ahmadbady.
AI-analyzed exploit summary This is a writeup describing a remote config file disclosure vulnerability in PollHelper. The vulnerability allows an attacker to access sensitive database credentials by directly accessing the poll.inc file.
Description
PollHelper stores poll.inc under the web root with insufficient access control, which allows remote attackers to download the database file containing user credentials via a direct request.
Exploits (1)
exploitdb
WRITEUP
VERIFIED
by ahmadbady · textwebappsphp
https://www.exploit-db.com/exploits/7690
This is a writeup describing a remote config file disclosure vulnerability in PollHelper. The vulnerability allows an attacker to access sensitive database credentials by directly accessing the poll.inc file.
Classification
Writeup 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target:
PollHelper (version not specified)
No auth needed
Prerequisites:
Access to the target web server
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026
Full analysis →
References (4)
Core 4
Core References
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/33378
Exploit vdb-entry
x_refsource_osvdb
http://osvdb.org/51185
Exploit, Third Party Advisory exploit
x_refsource_exploit-db
https://www.exploit-db.com/exploits/7690
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/47797
Scores
EPSS
0.0251
EPSS Percentile
82.7%
Details
CWE
CWE-264
Status
published
Products (1)
freedville/pollhelper
Published
Mar 05, 2009
Tracked Since
Feb 18, 2026