Loading HuntDB...

blog.praca.olx.pl database credentials exposure

Medium
O
OLX
Submitted None
Reported by hdbreaker

Vulnerability Details

Technical details and impact analysis

Information Disclosure
Hi, I found that the site blog.praca.olx.pl is exposing the content of wp-config.php file in plaintext due that a misconfiguration in the file-manager plugin. The information can be accessed here: http://blog.praca.olx.pl/wp-content/uploads/file-manager/log.txt The credentials are stored in the log.txt file as can be seen in the following image: {F379634} An attacker could use this information for further attacks. Regards, ## Impact An attacker could use this information for further attacks if the database access is achieved all the information of the blog will be in risk and could be used to achieved remote code execution via file upload in the admin panel.

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Information Disclosure