6.9 Medium
AI Score
Confidence
Low
0.01 Low
EPSS
Percentile
83.5%
Z-Blog 1.7 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for zblog.mdb.
osvdb.org/39739
securityreason.com/securityalert/2776
www.securityfocus.com/archive/1/470238/100/0/threaded
www.vupen.com/english/advisories/2007/2060
exchange.xforce.ibmcloud.com/vulnerabilities/34673