|
ASPRunner contains a flaw that may lead to an unauthorized information disclosure. With knowledge of the database file name a remote attacker could send a specially crafted URL request for this file to download the database, which will disclose sensitive information resulting in a loss of confidentiality.
|