Forum

Vulnerability in Pa...
 
Notifications
Clear all

Vulnerability in Paramters

5 Posts
3 Users
0 Reactions
1,458 Views
(@gg42)
Posts: 2
New Member
Topic starter
 
[#8970]

Hi everyone, 
I'm surprised to see in my parameters.php config file in filesconfig , database password is clear.
Any way to secure it ?

extract : 
[...]$paramDbPort='3306';
$paramDbUser='xpozl_projeq';
$paramDbPassword='passwordisclear';
$paramDbName='xpozl_projeq';
[...]

BR
Gerald
 


 
Posted : 18 Jul 2023 20H26
(@cecile)
Posts: 160
Member Admin
 

Hello,
Maybe that's why during installation there's a hint to set up a directory outside of web reach for this file 😉
 


 
Posted : 19 Jul 2023 11H08
(@gg42)
Posts: 2
New Member
Topic starter
 

Thanks, indeed have an outside directory may mitigate(only) this point. 
I am using the latest version (guess 14.2)
BTW, I setup an external directory on the server, I put in fields where logs and file are supposed to be, my configuration have been rejected by the system. 
external directioy is 10+ char long. Do you know if  any limit in size path exist?
cheers


 
Posted : 19 Jul 2023 11H47
(@babynus)
Posts: 14952
Member Admin
 

Do you know if  any limit in size path exist?

No, as far as I can remember, there is not limit, only system limits (255 chars on windows).


 
Posted : 19 Jul 2023 12H23
(@cecile)
Posts: 160
Member Admin
 

Also, did you check if you granted all the rights (read, update, delete...) on those directories ?
If you are on Windows, you may need to specify a full path access starting with a drive letter, and there may also be a confusion between and / in the path.


 
Posted : 19 Jul 2023 12H30
Share:

Scroll to Top