Exploit EZ Publish 2.2.7/3.0 - site.ini Information Disclosure

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
22488
Проверка EDB
  1. Пройдено
Автор
GREGORY LE BRAS
Тип уязвимости
REMOTE
Платформа
WINDOWS
CVE
null
Дата публикации
2003-04-15
Код:
source: https://www.securityfocus.com/bid/7347/info

eZ Publish has been reported prone to sensitive information disclosure vulnerability.

An attacker may make a request for and download the underlying site.ini configuration file. The file contains eZ Publish administration credentials stored in plaintext format. Any HTTP requests for this file will reveal the contents of this file to remote attackers. 

http://[target]/settings/site.ini
 
Источник
www.exploit-db.com

Похожие темы