mimicboard2 (Mimic2) 086 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for mimic2.dat.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Mimicboard | Chitta | * | mimiboard2_086 (including) |