BaalASP 2.0 - Database Disclosure
This is a writeup describing an information disclosure vulnerability in BaalASP 2.0, where the database file can be directly accessed via a predictable URL path. No exploit code is provided, only a URL path to the vulnerable resource.