CVE-2007-0094 Information

Description

Sven Moderow GuestBook 0.3a stores sensitive information under the web root with insufficient access control which allows remote attackers to download a database containing passwords via a direct request for (1) gbook97.mdb or (2) gbook.mdb in ~db/.

Reference

http://aria-security.com/forum/showthread.php?p=114 http://osvdb.org/33363 http://securityreason.com/securityalert/2105 http://www.securityfocus.com/archive/1/455788/100/0/threaded https://exchange.xforce.ibmcloud.com/vulnerabilities/31245

Share on: