PT-2005-1881 · Betaparticle · Betaparticle Blog

Dxil

·

Published

2005-03-24

·

Updated

2017-10-11

·

CVE-2005-0853

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions betaparticle blog (bp blog) versions prior to 3.0 betaparticle blog (bp blog) versions 3.0 through 9.0
Description The issue allows remote attackers to obtain sensitive information by directly requesting the database files. For versions before 3.0, this can be done via a direct request to "dbBlogMX.mdb". For versions 3.0 and later, as well as versions 6.0 through 9.0, the issue can be exploited by requesting "Blog.mdb".
Recommendations For versions prior to 3.0, consider moving the database file dbBlogMX.mdb outside of the web root to prevent direct access. For versions 3.0 through 9.0, restrict access to the Blog.mdb file to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-0853

Affected Products

Betaparticle Blog