Loading vulnerability details…
CVSS v3.1
N/A
EPSS
1.39%
Published
Feb 22, 2006
Modified
Jun 16, 2026
Public PoC / Exploit (1)
All weaponized →Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
Leif M. Wright's Blog 3.5 stores the config file and other txt files under the web root with insufficient access control, which allows remote attackers to read the administrator's password.
Affected Products (1)
References (10)