MetaCart2.sql stores the user database under the web document root without access controls, which allows remote attackers to obtain sensitive information such as passwords and credit card numbers via a direct request for metacart.mdb.
Score: 3.0
Priority: P2 - Serious (High)
Score: 0.00428
Percentile:
0.61632
CVSS v2 Score: 6.4
Severity: