Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2005-3347

Опубликовано: 18 нояб. 2005
Источник: ubuntu
Приоритет: medium
CVSS2: 6.8

Описание

Multiple directory traversal vulnerabilities in index.php in phpSysInfo 2.4 and earlier, as used in phpgroupware 0.9.16 and earlier, and egrouwpware before 1.0.0.009, allow remote attackers to include arbitrary files via .. (dot dot) sequences in the (1) sensor_program parameter or the (2) _SERVER[HTTP_ACCEPT_LANGUAGE] parameter, which overwrites an internal variable, a variant of CVE-2003-0536. NOTE: due to a typo in an advisory, an issue in osh was inadvertently linked to this identifier; the proper identifier for the osh issue is CVE-2005-3346.

РелизСтатусПримечание
dapper

released

1.0.0.009.dfsg-3-4
devel

released

1.0.0.009.dfsg-3-4
edgy

released

1.0.0.009.dfsg-3-4
feisty

released

1.0.0.009.dfsg-3-4
upstream

needs-triage

Показывать по

РелизСтатусПримечание
dapper

released

0.9.16.010-1
devel

released

0.9.16.010-1
edgy

released

0.9.16.010-1
feisty

released

0.9.16.010-1
upstream

needs-triage

Показывать по

РелизСтатусПримечание
dapper

released

2.3-7
devel

released

2.3-7
edgy

released

2.3-7
feisty

released

2.3-7
upstream

needs-triage

Показывать по

Ссылки на источники

6.8 Medium

CVSS2

Связанные уязвимости

nvd
почти 20 лет назад

Multiple directory traversal vulnerabilities in index.php in phpSysInfo 2.4 and earlier, as used in phpgroupware 0.9.16 and earlier, and egrouwpware before 1.0.0.009, allow remote attackers to include arbitrary files via .. (dot dot) sequences in the (1) sensor_program parameter or the (2) _SERVER[HTTP_ACCEPT_LANGUAGE] parameter, which overwrites an internal variable, a variant of CVE-2003-0536. NOTE: due to a typo in an advisory, an issue in osh was inadvertently linked to this identifier; the proper identifier for the osh issue is CVE-2005-3346.

debian
почти 20 лет назад

Multiple directory traversal vulnerabilities in index.php in phpSysInf ...

github
больше 3 лет назад

Multiple directory traversal vulnerabilities in index.php in phpSysInfo 2.4 and earlier, as used in phpgroupware 0.9.16 and earlier, and egrouwpware before 1.0.0.009, allow remote attackers to include arbitrary files via .. (dot dot) sequences in the (1) sensor_program parameter or the (2) _SERVER[HTTP_ACCEPT_LANGUAGE] parameter, which overwrites an internal variable, a variant of CVE-2003-0536. NOTE: due to a typo in an advisory, an issue in osh was inadvertently linked to this identifier; the proper identifier for the osh issue is CVE-2005-3346.

6.8 Medium

CVSS2