OSVDB ID: 18558

Title: Kathi O'Shea Guestbook Guestbook.mdb User Database Remote Disclosure

Info

Disclosure

Jul 29, 2005

Discovery

Unknown

Dates

Exploit

Jul 29, 2005

Solution

Unknown

Description

Guestbook contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when the guestbook.mdb file is stored in the server root by default, which will allow direct access to download the database file.

Classification

Location: Remote/Network Access Required
Attack Type: Information Disclosure
Impact: Loss of Confidentiality
Exploit: Exploit Available
OSVDB: Web Related

Solution

Currently, there are no known upgrades, patches, or workarounds available to correct this issue.

Products

Kathi O'Shea

Guestbook

Unknown or Unspecified

References

Credit

  • MeSa7eB - l--sBrand New Doo Doohotmail.com - Personal Site


Direct URL: http://osvdb.org/36218