id: qdpm-info-leak info: name: qdPM 9.2 - DB Credentials Exposure author: gy741 severity: high description: qdPM 9.2 database credentials were discovered. reference: - https://www.exploit-db.com/exploits/50176 metadata: max-request: 1 tags: qdpm,exposure,edb http: - method: GET path: - '{{BaseURL}}/core/config/databases.yml' matchers-condition: and matchers: - type: word part: body words: - 'dsn:' - 'username:' - 'password:' condition: and - type: status status: - 200 # digest: 490a00463044022074ef31ce73d11d18bd58053eb4ff8e9b11526e67311a2d6275d719886781a890022066d07ce9a757c8c4179b15ecb70390f866780d197046f47bed8e8b66eec099ad:922c64590222798bb761d5b6d8e72950