Vulnerabilities > CVE-2005-0853 - Remote vulnerability in Betaparticle Blog 2.0/3.0
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
NONE Availability impact
NONE Summary
betaparticle blog (bp blog) stores the database under the web root, which allows remote attackers to obtain sensitive information via a direct request to (1) dbBlogMX.mdb for versions before 3.0, or (2) Blog.mdb for versions 3.0 and later. NOTE: it was later reported that vector 2 also affects versions 6.0 through 9.0.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 2 |
Exploit-Db
description betaparticle blog 2.0/3.0 dbBlogMX.mdb Direct Request Database Disclosure. CVE-2005-0853. Webapps exploit for asp platform id EDB-ID:25252 last seen 2016-02-03 modified 2005-03-21 published 2005-03-21 reporter farhad koosha source https://www.exploit-db.com/download/25252/ title betaparticle blog 2.0/3.0 dbBlogMX.mdb Direct Request Database Disclosure id EDB-ID:7499
References
- http://seclists.org/lists/bugtraq/2005/Mar/0360.html
- http://secunia.com/advisories/14668
- http://secunia.com/advisories/33233
- http://www.securityfocus.com/bid/12861
- https://exchange.xforce.ibmcloud.com/vulnerabilities/19779
- https://exchange.xforce.ibmcloud.com/vulnerabilities/47419
- https://www.exploit-db.com/exploits/7499