Description
Macromedia Dreamweaver has created a directory (_mmServerScripts or _mmDBScripts) that contains scripts for testing database connectivity. One of these scripts (mmhttpdb.php or mmhttpdb.asp) can be accessed without user ID or password and contains numerous operations, such as listing Datasource Names or executing arbitrary SQL queries.
Remediation
Remove these directories from production systems.
References
Related Vulnerabilities
WordPress Plugin RSVPMaker SQL Injection (6.1.9)
WordPress Plugin NextGEN Gallery-WordPress Gallery Information Disclosure (1.9.11)
WordPress Plugin All Video Gallery 'vid' Parameter Multiple SQL Injection Vulnerabilities (1.1)
WordPress Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2015-5730)
WordPress Plugin Calculated Fields Form Multiple SQL Injection Vulnerabilities (1.0.10)