Vulnerabilities > CVE-2007-2100 - Information Disclosure vulnerability in FAC Guestbook FAC Guestbook 2.0

047910
CVSS 10.0 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
low complexity
fac-guestbook
critical

Summary

FAC Guestbook 2.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for db/Gdb.mdb.

Vulnerable Configurations

Part Description Count
Application
Fac_Guestbook
1