Mavili Guestbook could allow a remote attacker to obtain sensitive information, caused by improper restrictions on the guestbook.mdb file stored inside the Web root. By sending a direct request, an attacker could exploit this vulnerability to download the database file and obtain sensitive information.
Vendor Status:
Currently we are not aware of any vendor-supplied patches.