Description
8pixel.net Blog 4 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for App_Data/sb.mdb.
Affected products
- 8pixel / simple_blog4.0 – 4.0