5
CVSSv2

CVE-2008-6815

Published: 28/05/2009 Updated: 29/09/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

mykdownload.php in MyKtools 2.4 does not require administrative authentication, which allows remote malicious users to read a database backup by making a direct request, and then sending an unspecified request to the download page for the backup.

Vulnerable Product Search on Vulmon Subscribe to Product

myktools myktools 2.4

Exploits

MyKtools 24 Arbitrary Database Backup Vulnerability By : Mountassif Moad Exploit: localhost/mykdownloadphp after you get the page for download the backup # milw0rmcom [2008-10-27] ...