OWASP Mutillidae II - Sensitive Information Disclosure

OWASP Mutillidae II - Sensitive Information Disclosure

What is sensitive information disclosure vulnerability? When a website inadvertently provides users with sensitive information, this is known as sensitive information disclosure. We’ll be demonstrating a hardcoded credentials vulnerability utilizing the Client-side Comments page.

First, open the Client-side Comments page by navigating to the following location in the menu: HTML/Javascript comments

Sensitive Information Disclosure

Right click, then choose View Page Source

Sensitive Information Disclosure

The hard-coded login credentials are located in a comment at the bottom of the source code-containing page

Sensitive Information Disclosure

comments powered by Disqus
Hello world!
Built with Hugo
Theme Stack designed by Jimmy