vendor:
Ublog access version
by:
Cyber-Zone (ABDELKHALEK)
7,5
CVSS
HIGH
Arbitrary Database Disclosure
200
CWE
Product Name: Ublog access version
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2009
Ublog access version Arbitrary Database Disclosure Exploit
Ublog access version Arbitrary Database Disclosure Exploit is a perl script which exploits the vulnerability in the Ublog access version. It allows an attacker to access the mdb-database/blog.mdb file of the vulnerable website. The attacker can use the dork http://www.google.co.ma/search?q=index.asp%3Farchivio%3DOK&hl=fr&start=20&sa=N to search for vulnerable websites. The exploit uses the LWP::Simple and LWP::UserAgent modules to connect to the server and search for the file. If the file is found, the contents of the file are displayed.
Mitigation:
The user should ensure that the mdb-database/blog.mdb file is not accessible to the public.