Uapplication Uguestbook 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for mdb-database/guestbook.mdb.
References
Configurations
Information
Published : 2005-05-02 21:00
Updated : 2018-10-19 08:31
NVD link : CVE-2005-1425
Mitre link : CVE-2005-1425
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
uapplication
- uguestbook