Description
Macromedia Dreamweaver has created a directory (_mmServerScripts or _mmDBScripts) that contains scripts for testing database connectivity. One of these scripts (mmhttpdb.php or mmhttpdb.asp) can be accessed without user ID or password and contains numerous operations, such as listing Datasource Names or executing arbitrary SQL queries.
Remediation
Remove these directories from production systems.
References
Related Vulnerabilities
WordPress Plugin Relevanssi-A Better Search SQL Injection (3.6.0)
WordPress Plugin Pay With Tweet SQL Injection and Cross-Site Scripting Vulnerabilities (1.1)
WordPress Plugin iThemes Security (formerly Better WP Security) Multiple Vulnerabilities (3.6.3)
WordPress Plugin BuddyPress Multiple SQL Injection Vulnerabilities (1.7.1)