Discovered a new vulnerability in the shopping management system Comersus

July 1, 2003 a new vulnerability in the shopping Comersus management system was found.
A remote user (yes, the guy and you, too) can view the store database.
In a default configuration, to store a database stored in a directory of Web-server that is accessible to the remote user. In general, you drive in Action:
http: //www.victim.cov/database/comersus.mdb - and your database.
How to find shops with this system, you probably already know. Otherwise, why are you even reading this?
And for the lazy URLs here:
http://www.sjconsultinggroup.com/comersus/database/comersus.mdb
http://www.comwebtech.com.au/final/database/comersus.mdb
http://www.gardenofthegourds.com/database/comersus.mdb
http://www.jeswin.com/database/comersus.mdb
http://thetestoftime.com/database/comersus.mdb

True cards out there like there is no, but there is an admin password, though encrypted, but for those who want to decrypt it, I'll give urlik
http://forum.securitylab.ru/forum_posts.asp?TID=4418

durito