CVE-2009-0827

PollHelper - Unauthenticated Arbitrary File Download via Direct Request

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2009-0827. PoCs published by ahmadbady.

AI-analyzed exploit summary This is a writeup describing a remote config file disclosure vulnerability in PollHelper. The vulnerability allows an attacker to access sensitive database credentials by directly accessing the poll.inc file.

Description

PollHelper stores poll.inc under the web root with insufficient access control, which allows remote attackers to download the database file containing user credentials via a direct request.

Exploits (1)

exploitdb WRITEUP VERIFIED
by ahmadbady · textwebappsphp
https://www.exploit-db.com/exploits/7690

This is a writeup describing a remote config file disclosure vulnerability in PollHelper. The vulnerability allows an attacker to access sensitive database credentials by directly accessing the poll.inc file.

Classification
Writeup 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: PollHelper (version not specified)
No auth needed
Prerequisites: Access to the target web server
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (4)

Core 4
Core References
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/33378
Exploit vdb-entry x_refsource_osvdb
http://osvdb.org/51185
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/7690
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/47797

Scores

EPSS 0.0251
EPSS Percentile 82.7%

Details

CWE
CWE-264
Status published
Products (1)
freedville/pollhelper
Published Mar 05, 2009
Tracked Since Feb 18, 2026