[WEBISTE] Expose Symfony2 on ddragon.leagueoflegends.com

Grzonu·10/4/2016, 8:57:20 PM·1 votes·838 views

Hi,

I wanna report security issue on ddragon.leagueoflegends.com (CDN) - there is exposed app_dev.php (which should not be exposed on production - i know is locked but it still security issue), config.php is exposed too. And the most important thing is that all "bad people" see that is symfony 2 in background and can try to use some 0days if they show up(you can see in on favicon too)

0 Comments