MT Orumcek Toplist 2.2 stores DB/orumcektoplist.mdb under the web root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request.
Link | Tags |
---|---|
http://securityreason.com/securityalert/1235 | third party advisory |
http://www.securityfocus.com/archive/1/439611/100/0/threaded | mailing list |