logo

Database

Config Files Db Connection String Password

Description

The source code repository contains sensitive information: DB Connection String with Password

Weakness:

009 - Sensitive information in source code

Category: Information Collection

Detection Strategy

    Matches DB Connection String with Password patterns in source code and configuration files

Vulnerable code example

connectionString="Server=db;password=secret123"
connectionString="Data Source=.;Password=admin;User=sa"