aspWebCalendar Free Edition bug Mar 31 2009 03:46AM
joseph giron13 gmail com
I'm not sure how to classify this bug / vulnerability, but for aspWebCalendar Free edition, you can openly download the mdb file and read its contents (username,pasword).

Example

http://www.example.com/calendar/calendar.mdb

I guess the fix would be to place the mdb file outside of wwwroot.

[ reply ]


 

Privacy Statement
Copyright 2010, SecurityFocus