4 ms·
> Assuming there are no other bugs in the CMS in question, and no other apps are installed with access to the same server, and the admins implement good authent
by Ergomane 14y ago
> Assuming there are no other bugs in the CMS in question, and no other apps are installed with access to the same server, and the admins implement good authentication policies, there is no danger from this.
That depends on the contents of the file in question. Example: An attacker can forge hmacs if the config file contains the signing key.