Capital Request Forms stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain database credentials via a direct request for inc/common_db.inc.
Publication date: Tue, 13 Feb 2007 02:28:00 +0000