CVE-2009-3199
Uebimiau Webmail 3.2.0-2.0 - Unauthenticated Exposure of Sensitive Information via Direct Request
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-3199. PoCs published by Septemb0x.
AI-analyzed exploit summary This is a writeup describing an arbitrary admin database disclosure vulnerability in Uebimiau Webmail. It provides examples of vulnerable URLs and explains how to exploit the issue to retrieve admin credentials.
Description
Uebimiau Webmail 3.2.0-2.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database with usernames and password hashes via a direct request for system_admin/admin.ucf.
Exploits (1)
This is a writeup describing an arbitrary admin database disclosure vulnerability in Uebimiau Webmail. It provides examples of vulnerable URLs and explains how to exploit the issue to retrieve admin credentials.