blog.praca.olx.pl database credentials exposure
Medium
O
OLX
Submitted None
Actions:
Reported by
hdbreaker
Vulnerability Details
Technical details and impact analysis
Hi, I found that the site blog.praca.olx.pl is exposing the content of wp-config.php file in plaintext due that a misconfiguration in the file-manager plugin.
The information can be accessed here: http://blog.praca.olx.pl/wp-content/uploads/file-manager/log.txt
The credentials are stored in the log.txt file as can be seen in the following image:
{F379634}
An attacker could use this information for further attacks.
Regards,
## Impact
An attacker could use this information for further attacks if the database access is achieved all the information of the blog will be in risk and could be used to achieved remote code execution via file upload in the admin panel.
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Information Disclosure