This is a writeup describing a path disclosure vulnerability in Web Wiz Forums v9.64, where the database file can be accessed directly via a predictable URL. No exploit code is provided, only a description and a dork for finding vulnerable instances.
Classification
Writeup 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target:Web Wiz Forums v9.64
No auth needed
Prerequisites:Target must be running Web Wiz Forums v9.64 with default or predictable database path