CVE

Id
43249  
CVE No.
CVE-2010-0665  
Status
Candidate  
Description
JAG (Just Another Guestbook) 1.14 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request for jag/database.sql.  
Phase
Assigned (20100219)  
Votes
None (candidate not yet proposed)  
Comments