vendor:
ASP Football Pool
by:
ALBAYX
7,5
CVSS
HIGH
Remote Database Disclosure
200
CWE
Product Name: ASP Football Pool
Affected Version From: v2.3
Affected Version To: v2.3
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2009
ASP Football Pool v2.3 Remote Database Disclosure Exploit
This exploit allows an attacker to gain access to the remote database of ASP Football Pool v2.3. The exploit uses the LWP::UserAgent module to send a request to the target URL and download the database file (NFL.mdb) to the attacker's machine.
Mitigation:
Upgrade to the latest version of ASP Football Pool v2.3