CVE-2012-5298 Information

Description

Mavili Guestbook as released in November 2007 stores guestbook.mdb under the web root with insufficient access control which allows remote attackers to read the database via a direct request.

Reference

http://archives.neohapsis.com/archives/bugtraq/2012-01/0010.html http://code.google.com/p/maviliguestbook/issues/detail?id=1 http://www.securityfocus.com/bid/51252 https://exchange.xforce.ibmcloud.com/vulnerabilities/72101

Share on: