System Error Reveals SQL Information

Disclosed: 2021-09-09 19:59:23 By miguel_santareno To deptofdefense
Medium
Vulnerability Details
Hello, While testing your program i came across an endpoint that is leaking sql errors and queries from on of your websites. I use the following google dork to detect this: site:████████ "sql error" Endpoints leaking data: https://www.██████/██████████ https://www.███████/███ Some of the errors found on https://www.███/█████: SQLSTATE █████████ DATASOURCE ███ VENDORERRORCODE ███ SQL SELECT █████████, █████', '█████████, ██████, ████, ███████, ███████, ████████ (..) ██████████-████████: ██████" ████" ███ ████ ██████████ ████ █████ (..) Some of the errors found on https://www.███████/████: SQLSTATE █████████ DATASOURCE █████ VENDORERRORCODE ███ SQL SELECT ██████████ ███████ ███████, ██████, ██████, █████, █████, ████████ (...) █████████-███: ███████" █████" ██████ ███████ ████ █████ ██████████ (...) Best Regards Miguel Santareno ## Impact Attacker can use the error messages to gain further knowledge of the SQL system to launch future attacks. ## System Host(s) www.███████ ## Affected Product(s) and Version(s) ## CVE Numbers ## Steps to Reproduce Open the following endpoints https://www.██████████/█████ and https://www.█████████/███████ and you should be able to see the information above mentioned. ## Suggested Mitigation/Remediation Actions Remove any mention of the SQL database calls in the stack trace error.
Actions
View on HackerOne
Report Stats
  • Report ID: 1272095
  • State: Closed
  • Substate: resolved
  • Upvotes: 2
Share this report