CVE-2010-0665
JAG 1.14 - Unauthenticated Sensitive Information Exposure via Direct Request
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2010-0665. PoCs published by Phenom.
AI-analyzed exploit summary This exploit discloses the path to the database file in J.A.G (Just Another Guestbook) v1.14, allowing unauthorized access to sensitive data. The vulnerability is exploited by directly accessing the database.sql file via a predictable URL path.
Description
JAG (Just Another Guestbook) 1.14 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request for jag/database.sql.
Exploits (1)
This exploit discloses the path to the database file in J.A.G (Just Another Guestbook) v1.14, allowing unauthorized access to sensitive data. The vulnerability is exploited by directly accessing the database.sql file via a predictable URL path.