Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2006-3360

Опубликовано: 06 июл. 2006
Источник: debian
EPSS Низкий

Описание

Directory traversal vulnerability in index.php in phpSysInfo 2.5.1 allows remote attackers to determine the existence of arbitrary files via a .. (dot dot) sequence and a trailing null (%00) byte in the lng parameter, which will display a different error message if the file exists.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
phpsysinfofixed3.2.5-3package
egroupwareunfixedpackage
phpgroupwareunfixedpackage

Примечания

  • https://github.com/phpsysinfo/phpsysinfo/commit/60b5bbb5d1cc17f44050e99a3e746f55a4fd4e18 (v3.2.5)

  • Only the existence of files inside the WWW root is leaked. If this is

  • a threat to your setup you most probably shouldn't install a script which

  • exposes all your system data, either.

EPSS

Процентиль: 93%
0.09364
Низкий

Связанные уязвимости

ubuntu
около 19 лет назад

Directory traversal vulnerability in index.php in phpSysInfo 2.5.1 allows remote attackers to determine the existence of arbitrary files via a .. (dot dot) sequence and a trailing null (%00) byte in the lng parameter, which will display a different error message if the file exists.

nvd
около 19 лет назад

Directory traversal vulnerability in index.php in phpSysInfo 2.5.1 allows remote attackers to determine the existence of arbitrary files via a .. (dot dot) sequence and a trailing null (%00) byte in the lng parameter, which will display a different error message if the file exists.

github
больше 3 лет назад

phpSysInfo allows remote attackers to determine the existence of arbitrary files via a .. (dot dot) sequence

EPSS

Процентиль: 93%
0.09364
Низкий