Possible Database Connection String Detected on Target Web Application
Netsparker detected a possible database connection string on your web server.
Depending on the nature of the connection string disclosed, an attacker can mount one or more of the following types of attacks:
- Access the database or other data resources. With the privileges of the account obtained; attempt to read, update or delete arbitrary data from the database.
- Access password protected administrative mechanisms such as "dashboard", "management console" and "admin panel" potentially leading to full control of the application.
Actions to Take
- Remove all the database connection strings on the public web pages.