SimplePHPBlog 0.4.0 stores password hashes in config/password.txt with insufficient access control, which allows remote attackers to obtain passwords via a brute force attack.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Simple_php_blog | Alexander_palmo | 0.4.0 (including) | 0.4.0 (including) |