Google Search: intitle:dupics inurl:(add.asp | default.asp | view.asp | voting.asp) -site:duware.com
murfie rates this entry 10 out of 10.
Submitted: 2004-11-23 16:38:25
Added by: murfie
Most duware products use Microsoft Access databases in default locations without instructing the users to change them. The plain text admin passwords are just a click away for any attacker who knows how to type an URL. For Dupics rename location to ../_private/dupics.mdb