This is a writeup describing an information disclosure vulnerability in Net Gitar Shop v1.0, where the database file (db.mdb) can be directly accessed via a URL. No exploit code is provided, only a path disclosure.
Classification
Writeup 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target:Net Gitar Shop v1.0
No auth needed
Prerequisites:Target must have the vulnerable software installed with default configurations