Error logs are exposed in MangoBlog
Heard about this from the cfhour podcast so it's in the wild. I'm emailing Laura on this as well, but it may take some time for an update to fix this can get released.
Basically, MangoBlog logs certain errors into *.htm files in blog\components\utilities\logs. Since they are html files they are directly accessible for the world to see. If you are using MangoBlog, you will want to modify the logMessage method inside blog\components\utilities\Logger.cfc to point either to a protected area or to turn this logic off. Hopefully, an update to MangoBlog will allow for control of this functionality from the admin.
Mike Henke wrote on 12/30/096:44 PM
How about a plugin to fix this? I haven't created any but I would think someone could whip up a quick fix via a plugin.