CVE-2008-5931
21.01.2009, 18:30
The Net Guys ASPired2Blog stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing usernames and passwords via a direct request for admin/blog.mdb. NOTE: some of these details are obtained from third party information.Enginsight
Vendor | Product | Version |
---|---|---|
the_net_guys | aspired2blog | * |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References