Loading HuntDB...

Full Path and internal information disclosure+ SQLNet.log file disclose internal network information

Low
U
Uber
Submitted None

Team Summary

Official summary from Uber

The site at lab.usuppliers.uber.com was intended only for authenticated users, but certain internal pages did not enforce an authentication requirement. The log file at /OA_HTML/bin/sqlnet.log disclosed internal Uber IP addresses, hostnames, and one internal username. Thanks again for this report @peroni!

Reported by peroni

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted