CVE-2009-5019
Web Wiz NewsPad - Unauthenticated Sensitive Information Exposure via Direct Database Request
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2009-5019. PoCs published by keracker, ViRuSMaN.
AI-analyzed exploit summary This is a writeup describing a vulnerability in NewsPad that allows unauthorized database download. It provides a path to exploit but lacks executable code or detailed technical steps.
Description
Web Wiz NewsPad stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for database/NewsPad.mdb.
Exploits (2)
This is a writeup describing a vulnerability in NewsPad that allows unauthorized database download. It provides a path to exploit but lacks executable code or detailed technical steps.
This is a writeup describing a path disclosure vulnerability in Web Wiz NewsPad. The exploit details how an attacker can access the database file directly via a predictable path.