CVE-2009-0828

QuoteBook - Info Disclosure

Title source: llm

Description

QuoteBook stores quotes.inc under the web root with insufficient access control, which allows remote attackers to obtain sensitive database information, including user credentials, via a direct request.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Moudi · textwebappsphp
https://www.exploit-db.com/exploits/7699

Scores

EPSS 0.0643
EPSS Percentile 90.9%

Classification

CWE
CWE-264
Status draft

Affected Products (1)

freedville/quotebook

Timeline

Published Mar 05, 2009
Tracked Since Feb 18, 2026