qdPM 9.2 – Password Exposure (Unauthenticated)

  • 作者: Leon Trappett
    日期: 2021-08-04
  • 类别:
    平台:
  • 来源:https://www.exploit-db.com/exploits/50176/
  • # Exploit Title: qdPM 9.2 - DB Connection String and Password Exposure (Unauthenticated)
    # Date: 03/08/2021
    # Exploit Author: Leon Trappett (thepcn3rd)
    # Vendor Homepage: https://qdpm.net/
    # Software Link: https://sourceforge.net/projects/qdpm/files/latest/download
    # Version: 9.2
    # Tested on: Ubuntu 20.04 Apache2 Server running PHP 7.4
    
    The password and connection string for the database are stored in a yml file. To access the yml file you can go to http://<website>/core/config/databases.yml file and download.