[原文]Uapplication Uguestbook 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for mdb-database/guestbook.mdb.
Uguestbook guestbook.mdb Remote Information Disclosure
Remote / Network Access
Loss of Confidentiality
Ugestbook contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a remote attacker directly requests the 'guestbook.mdb' file, which will disclose user login and password information resulting in a loss of confidentiality.
Currently, there are no known upgrades, patches, or workarounds available to correct this issue.