CodefixerSoftware MailingListPro Free Edition stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request to db/MailingList.mdb.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Mailinglistpro | Codefixer | –free (including) | –free (including) |