symfony-database-config: Symfony Database Configuration File - Detect

日期: 2025-08-01 | 影响软件: Symfony Database Config | POC: 已公开

漏洞描述

Symfony database configuration file was detected and may contain database credentials.

PoC代码[已公开]

id: symfony-database-config

info:
  name: Symfony Database Configuration File - Detect
  author: pdteam,geeknik
  severity: high
  description: Symfony database configuration file was detected and may contain database credentials.
  reference:
    - https://symfony.com/legacy/doc/reference/1_3/en/07-Databases
  classification:
    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
    cvss-score: 7.5
    cwe-id: CWE-200
  metadata:
    max-request: 1
  tags: config,exposure,symfony,vuln

http:
  - method: GET
    path:
      - "{{BaseURL}}/config/databases.yml"

    matchers-condition: and
    matchers:
      - type: word
        part: header
        words:
          - "text/html"
        negative: true

      - type: status
        status:
          - 200

      - type: word
        words:
          - "class:"
          - "param:"
        condition: and
        part: body
# digest: 4b0a00483046022100b5fa6509a27a27610bbcf2cddab4b47abf9176623ccb87165829e0f3557c786f022100f0eb967e6b12d0de2521c9e3fe461fc9214c69032cc85e9538757db0cc33174d:922c64590222798bb761d5b6d8e72950