Detected SAP systems where the SAP Start Service (sapstartsrv) SAPControl SOAP interface exposes the ReadConfigFile web method in combination with an unprotected ListConfigFiles call, allowing unauthenticated reading of the global DEFAULT.PFL profile.
Log in to view the POC file snapshot cached by Shenlong Bot
Log in to view