[原文]Bannermatic 1, 2, and 3 stores the (1) ban.log, (2) ban.bak, (3) ban.dat and (4) banmat.pwd data files under the web document root with insufficient access control, which allows attackers to obtain sensitive information via a direct request for the files.
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: email@example.com .
Bannermatic Multiple File Direct Request Information Disclosure
Remote / Network Access
Loss of Confidentiality
Bannermatic contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a remote attacker attempts to read ban.log, ban.bak, ban.dat, or banmat.pwd which will disclose the information contained in those files resulting in a loss of confidentiality.
Currently, there are no known upgrades, patches, or workarounds available to correct this issue.