Uapplication Ublog Reload stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for mdb-database/blog.mdb (aka mdb-database/blog.msb).
Name | Vendor | Start Version | End Version |
---|---|---|---|
Ublog | Uapplication | * | * |