Forum Moderators: open

Message Too Old, No Replies

Remote Compromise Vulnerability in Dreamweaver

         

bill

12:39 am on Apr 15, 2004 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



Article [macromedia.com]
Dreamweaver by default creates and uploads a script to test remote database connectivity (mmhttpdb.asp) to the database-driven Web site being tested. If left on the server, the script can let a potential attacker access to the back-end database server without supplying a user ID and password.