Uapplication Ublog Reload stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for mdb-database/blog.mdb (aka mdb-database/blog.msb).
References
Configurations
Information
Published : 2005-05-02 21:00
Updated : 2017-10-10 18:30
NVD link : CVE-2005-1426
Mitre link : CVE-2005-1426
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
uapplication
- ublog