This is a writeup describing a remote configuration file disclosure vulnerability in phpEmployment. The exploit details a path traversal to access the configuration file at /conf/conf.inc.
Classification
Writeup 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target:phpEmployment (version not specified)
No auth needed
Prerequisites:access to the target web application