Lebisoft Ziyaretci Defteri 7.4 and 7.5 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for db/lebisoft.mdb.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Ziyaretci_defteri | Lebisoft | 7.4 (including) | 7.4 (including) |
Ziyaretci_defteri | Lebisoft | 7.5 (including) | 7.5 (including) |