Minb Is Not a Blog (minb) stores sensitive information under the web root with insufficient access control, which allows remote malicious users to download a database containing usernames and encrypted passwords via a direct request for db/users.db.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
minb minb is not a blog 0.1.0 |