header-logo
Suggest Exploit
vendor:
KMSoft Guestbook
by:
LionTurk
7,5
CVSS
HIGH
Database Disclosure
200
CWE
Product Name: KMSoft Guestbook
Affected Version From: 1.0
Affected Version To: 1.0
Patch Exists: No
Related CWE: N/A
CPE: a:kmsoft:kmsoft_guestbook:1.0
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2009

KMSoft Guestbook v 1.0 Database Disclosure Vulnerability

KMSoft Guestbook v 1.0 is vulnerable to a database disclosure vulnerability. An attacker can exploit this vulnerability by sending a malicious HTTP request to the vulnerable server. The request will return the database file (db.mdb) which contains sensitive information such as usernames, passwords, etc. The vulnerable URL is http://server/[dizin]/db/db.mdb.

Mitigation:

The best way to mitigate this vulnerability is to restrict access to the vulnerable URL. The web server should be configured to deny access to the db.mdb file.
Source

Exploit-DB raw data:

==============================================================================  

                      _      _       _          _      _   _  

                     / \    | |     | |        / \    | | | |  

                    / _ \   | |     | |       / _ \   | |_| |  

                   / ___ \  | |___  | |___   / ___ \  |  _  |  

                  /_/   \_\ |_____| |_____| /_/   \_\ |_| |_|  

   

   

==============================================================================  

        [»] ~ Note : Mutlu Yillar Millettt

==============================================================================  

        [»]KMSoft Guestbook v 1.0 Database Disclosure Vulnerability  

==============================================================================  

   

    [»] Script:             [ KMSoft Guestbook v 1.0 ]  

    [»] Language:           [ ASP ]  

    [»] Download:           [ http://kmsoft.org] 

    [»] Founder:            [ LionTurk -  Bylionturk@kafam1milyon.com }

    [»] My Home:            [ RevengeHack.com & Ar-ge.Org]  

    [»]N0T3    :             Yeni Aciklarimi Bekleyin.


###########################################################################  

   

===[ Exploit And Dork  ]===  

   

  [»] http://server/[dizin]/db/db.mdb

 


  [»] KMSoft Guestbook v 1.0 Powered by KMSoft or  Powered by KMSoft

  [»]   Admin Page: /admin



Author:  LionTurk <-  

Bizim Asiret: eXceptioN,CodeInside,CristaL1o,Hack3ra,eXtReMe,By_HKC,TerrorZveng
Ar-ge.Org :Cyber_945,D3xer

                 
- Kritik Benim,Kritigi Ben Bellerim,Kýzdýrmayýn Benim Alayinizi Keserim
- Ben Ne Heykirlar Gordum  site heyklicek exploiti yok.Ben Ne exploitler gordum kullancak heykir yok :D

                                 


###########################################################################