CVE-2009-2602

R2 Newsletter Lite/Pro/Stats - Info Disclosure

Title source: llm
STIX 2.1

Description

R2 Newsletter Lite, Pro, and Stats stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for admin.mdb.

Exploits (1)

exploitdb WORKING POC VERIFIED
by TiGeR-Dz · textwebappsasp
https://www.exploit-db.com/exploits/8849

References (2)

Core 2
Core References
Exploit, Third Party Advisory exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/8849
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/35312

Scores

EPSS 0.0369
EPSS Percentile 88.0%

Details

CWE
CWE-264
Status published
Products (3)
r2newsletter/r2_newsletter_lite
r2newsletter/r2_newsletter_pro
r2newsletter/r2_newsletter_stats
Published Jul 27, 2009
Tracked Since Feb 18, 2026