CVE-2009-0828

Publication date

2009-03-05 20:00:00

Family

mitre

State

PUBLISHED

Description

QuoteBook stores quotes.inc under the web root with insufficient access control, which allows remote attackers to obtain sensitive database information, including user credentials, via a direct request.