betaparticle blog (bp blog) stores the database under the web root, which allows remote malicious users to obtain sensitive information via a direct request to (1) dbBlogMX.mdb for versions prior to 3.0, or (2) Blog.mdb for versions 3.0 and later. NOTE: it was later reported that vector 2 also affects versions 6.0 up to and including 9.0.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
betaparticle betaparticle blog 2.0 |
||
betaparticle betaparticle blog 3.0 |