CVE-2009-0828
QuoteBook - Unauthenticated Sensitive Information Exposure via Direct Request to quotes.inc
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-0828. PoCs published by Moudi.
AI-analyzed exploit summary This is a writeup describing a file disclosure vulnerability in QuoteBook. The exploit details how accessing a specific file (poll.inc) can leak database credentials due to improper configuration handling.
Description
QuoteBook stores quotes.inc under the web root with insufficient access control, which allows remote attackers to obtain sensitive database information, including user credentials, via a direct request.
Exploits (1)
This is a writeup describing a file disclosure vulnerability in QuoteBook. The exploit details how accessing a specific file (poll.inc) can leak database credentials due to improper configuration handling.