Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:18651
HistoryDec 16, 2007 - 12:00 a.m.

PHP MySQL Banner Exchange 2.2.1 remote mysql database bug

2007-12-1600:00:00
vulners.com
36

Discovered by Arsalan kashan
[email protected]
portal=PHP MySQL Banner Exchange
download=http://sourceforge.net/projects/banex
version=2.2.1
bug:
its store the mysql database setting in a .inc file and you can easily read it as a anonymous user
/script_path/inc/lib.inc
the you can connect to mysql database