VendorsNoah Medlingrcblogall versions
Vulnerabilities

Noah Medling Rcblog

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2006-0371
Directory traversal vulnerability in index.php in Noah Medling RCBlog 1.03 allows remote attackers to read arbitrary .txt files, possibly including one that stores the administrator's account name and password, via a .. (dot dot) in the post parameter.
Published 2006-01-22 · Modified
5.0EPSS 0.029
CVE-2006-0370
Noah Medling RCBlog 1.03 stores the data and config directories under the web root with insufficient access control, which allows remote attackers to view account names and MD5 password hashes.
Published 2006-01-22 · Modified
5.0EPSS 0.018