CVE-2009-5019

Web Wiz NewsPad - Unauthenticated Sensitive Information Exposure via Direct Database Request

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2009-5019. PoCs published by keracker, ViRuSMaN.

AI-analyzed exploit summary This is a writeup describing a vulnerability in NewsPad that allows unauthorized database download. It provides a path to exploit but lacks executable code or detailed technical steps.

Description

Web Wiz NewsPad stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for database/NewsPad.mdb.

Exploits (2)

exploitdb WRITEUP VERIFIED
by keracker · textwebappsasp
https://www.exploit-db.com/exploits/15544

This is a writeup describing a vulnerability in NewsPad that allows unauthorized database download. It provides a path to exploit but lacks executable code or detailed technical steps.

Classification
Writeup 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Theoretical
Target: NewsPad (version unspecified)
No auth needed
Prerequisites: knowledge of the target path to the database
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WRITEUP VERIFIED
by ViRuSMaN · textwebappsasp
https://www.exploit-db.com/exploits/10637

This is a writeup describing a path disclosure vulnerability in Web Wiz NewsPad. The exploit details how an attacker can access the database file directly via a predictable path.

Classification
Writeup 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Web Wiz NewsPad (version not specified)
No auth needed
Prerequisites: Target must have Web Wiz NewsPad installed with default or predictable database path
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/55043
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/15544
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/10637

Scores

EPSS 0.0279
EPSS Percentile 84.6%

Details

CWE
CWE-264
Status published
Products (4)
webwiz/web_wiz_newspad 1.0
webwiz/web_wiz_newspad 1.01
webwiz/web_wiz_newspad 1.02
webwiz/web_wiz_newspad 1.03
Published Dec 01, 2010
Tracked Since Feb 18, 2026