PCI v3.2-6.5.5
CAPEC-118
CWE-201
HIPAA-164.306(a)
ISO27001-A.18.1.3
WASC-13
OWASP 2013-A5
OWASP 2017-A6

Database Name Disclosure (MySQL)

Severity:
Low
Summary

Invicti identified a database name disclosure (MySQL) in the error message.

Impact

An attacker can perform brute-force or dictionary-based password guessing on the disclosed database name. It may also help the attacker identify other vulnerabilities or further their exploitation of other identified vulnerabilities.

Remediation
  • Error messages should be disabled.
  • Remove this kind of sensitive data from the output.
Required Skills for Successful Exploitation
Actions To Take
Vulnerability Index

You can search and find all vulnerabilities

Select Vulnerability
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.