Vulnerabilities > CVE-2007-3083 - Information Disclosure vulnerability in Rainbowsoft Z-Blog 1.7

047910
CVSS 7.8 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
NONE
Availability impact
NONE
network
low complexity
rainbowsoft

Summary

Z-Blog 1.7 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for zblog.mdb.

Vulnerable Configurations

Part Description Count
Application
Rainbowsoft
1