Exploitation Summary
EIP tracks 1 public exploit for CVE-2009-4545. PoCs published by ZoRLu.
AI-analyzed exploit summary This exploit demonstrates an authentication bypass vulnerability in Logoshows BBS 2.0 by manipulating cookies to gain admin privileges. The PoC uses JavaScript to set cookies for username and privilege level, allowing unauthorized access.
Description
Logoshows BBS 2.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for database/globepersonnel.mdb.
Exploits (1)
This exploit demonstrates an authentication bypass vulnerability in Logoshows BBS 2.0 by manipulating cookies to gain admin privileges. The PoC uses JavaScript to set cookies for username and privilege level, allowing unauthorized access.