Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2006-3360

Опубликовано: 06 июл. 2006
Источник: debian

Описание

Directory traversal vulnerability in index.php in phpSysInfo 2.5.1 allows remote attackers to determine the existence of arbitrary files via a .. (dot dot) sequence and a trailing null (%00) byte in the lng parameter, which will display a different error message if the file exists.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
phpsysinfofixed3.2.5-3package
egroupwareunfixedpackage
phpgroupwareunfixedpackage

Примечания

  • https://github.com/phpsysinfo/phpsysinfo/commit/60b5bbb5d1cc17f44050e99a3e746f55a4fd4e18 (v3.2.5)

  • Only the existence of files inside the WWW root is leaked. If this is

  • a threat to your setup you most probably shouldn't install a script which

  • exposes all your system data, either.

Связанные уязвимости

ubuntu
больше 19 лет назад

Directory traversal vulnerability in index.php in phpSysInfo 2.5.1 allows remote attackers to determine the existence of arbitrary files via a .. (dot dot) sequence and a trailing null (%00) byte in the lng parameter, which will display a different error message if the file exists.

nvd
больше 19 лет назад

Directory traversal vulnerability in index.php in phpSysInfo 2.5.1 allows remote attackers to determine the existence of arbitrary files via a .. (dot dot) sequence and a trailing null (%00) byte in the lng parameter, which will display a different error message if the file exists.

github
почти 4 года назад

phpSysInfo allows remote attackers to determine the existence of arbitrary files via a .. (dot dot) sequence