Simple PHP Blog (sphpBlog) 0.4.0 stores the (1) password.txt and (2) config.txt files under the web document root, which allows remote attackers to obtain sensitive information and crack passwords via a direct request to these files.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Sphpblog | Sphpblog | 0.4_.0 (including) | 0.4_.0 (including) |