Medium
CVSS 5.0
Overview
KMSoft Guestbook (aka GBook) 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for db/db.mdb.
KMSoft Guestbook (aka GBook) 1.0 stores sensitive information under the web root...
KMSoft Guestbook (aka GBook) 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for db/db.mdb.
This vulnerability is rated 🟡 MEDIUM.
Recommended actions: