Virtual GuestBook (vgbook) 2.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request to guestbook.mdb.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Virtual_guestbook | Minitdesign | 2.1 (including) | 2.1 (including) |