Database Connection String Hardcoded Password

Description

The source code repository contains sensitive information: DB Connection String with Password

Weakness:

009 - Sensitive information in source code

Category: Information Collection

Detection Strategy

    Matches DB Connection String with Password patterns in source code and configuration files

Vulnerable code example

Server=localhost;Initial Catalog=master;User ID=sa;Password=P@ssw0rd!
Data Source=db.example.com;Initial Catalog=app;User ID=admin;Password=S3cr3t!
Server=myserver;Database=mydb;User Id=sa;pwd=hunter2;Encrypt=true
Network Address=10.0.0.1;Database=prod;User=app;Password=p@ssw0rd123