Uapplication Ublog Reload stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for mdb-database/blog.mdb (aka mdb-database/blog.msb).
References
Configurations
History
No history.
Information
Published : 2005-05-03 04:00
Updated : 2017-10-11 01:30
NVD link : CVE-2005-1426
Mitre link : CVE-2005-1426
CVE.ORG link : CVE-2005-1426
JSON object : View
Products Affected
uapplication
- ublog
CWE
CWE-264
Permissions, Privileges, and Access Controls