Local File Disclosure on the ████████ (https://████/) leads to the source code disclosure & DB credentials leak

Disclosed: 2021-01-12 21:53:16 By sp1d3rs To deptofdefense
High
Vulnerability Details
##Description I discovered another LFD on the https://████/ (virtual host on the █████ IP) ##POC https://█████/file.ashx?path=web.config will download the website configuration file. It exposes different DB credentials than in previous reports: ███ Similarly, attacker able to get content of any server-side file, such as source code of application: https://███/file.ashx?path=index.aspx ## Impact Source code & sensitive configuration data leakage. Attacker can use it to compromise the resource.
Actions
View on HackerOne
Report Stats
  • Report ID: 685344
  • State: Closed
  • Substate: resolved
  • Upvotes: 14
Share this report