CVE-2010-1736
KrM Haber 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for d_atabase/Krmdb.mdb.
Date published : 2010-05-06
http://packetstormsecurity.org/1004-exploits/krmhaber-disclose.txt