[原文]Uapplication Ublog Reload stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for mdb-database/blog.mdb (aka mdb-database/blog.msb).
Ublog Reload blog.msb Remote Information Disclosure
Remote / Network Access
Loss of Confidentiality
Ublog contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a remote attacker directly requests the 'blog.msb' file, which will disclose user login and password information resulting in a loss of confidentiality.
Currently, there are no known upgrades, patches, or workarounds available to correct this issue.