lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Message-ID: <20071214084216.6851.qmail@securityfocus.com> Date: 14 Dec 2007 08:42:16 -0000 From: arsalan1991@...il.com To: bugtraq@...urityfocus.com Subject: PHP MySQL Banner Exchange 2.2.1 remote mysql database bug Discovered by Arsalan kashan email=arsalan1991@...il.com portal=PHP MySQL Banner Exchange download=http://sourceforge.net/projects/banex version=2.2.1 bug: its store the mysql database setting in a .inc file and you can easily read it as a anonymous user /script_path/inc/lib.inc the you can connect to mysql database