Vulnerabilities > CVE-2007-0094 - Information Disclosure vulnerability in Sven Moderow Sven Moderow Guestbook 0.3A

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
sven-moderow

Summary

Sven Moderow GuestBook 0.3a stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for (1) gbook97.mdb or (2) gbook.mdb in ~db/.

Vulnerable Configurations

Part Description Count
Application
Sven_Moderow
1