Sven Moderow GuestBook 0.3a stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for (1) gbook97.mdb or (2) gbook.mdb in ~db/.
References
Configurations
History
No history.
Information
Published : 2007-01-05 18:28
Updated : 2024-02-28 11:01
NVD link : CVE-2007-0094
Mitre link : CVE-2007-0094
CVE.ORG link : CVE-2007-0094
JSON object : View
Products Affected
sven_moderow
- sven_moderow_guestbook
CWE