Exploitation Summary
EIP tracks 1 public exploit for CVE-2009-2022. PoCs published by ByALBAYX.
AI-analyzed exploit summary This is a writeup describing an information disclosure vulnerability in fipsCMS Light 2.1, where the database file (db.mdb) is exposed publicly. No exploit code is provided, only a demonstration of the vulnerability.
Description
fipsCMS Light 2.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file and obtain sensitive information via a direct request for _fipsdb/db.mdb.
Exploits (1)
This is a writeup describing an information disclosure vulnerability in fipsCMS Light 2.1, where the database file (db.mdb) is exposed publicly. No exploit code is provided, only a demonstration of the vulnerability.