AlstraSoft Web Host Directory stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a backup database via a direct request for admin/backup/db.
Publication date: Fri, 29 Dec 2006 17:28:00 +0000