CVE-2006-3360
EPSS 7.9%phpSysInfo allows remote attackers to determine the existence of arbitrary files via a .. (dot dot) sequence
發布日:2022/5/1修改日:2026/5/27
描述
Directory traversal vulnerability in index.php in phpSysInfo 2.5.1 allows remote attackers to determine the existence of arbitrary files via a .. (dot dot) sequence and a trailing null (%00) byte in the lng parameter, which will display a different error message if the file exists.
受影響套件(2)
- Debian/phpsysinfofrom 0, < 3.2.5-3
- Packagist/phpsysinfo/phpsysinfofrom 0, < 3.2.5
參考連結(7)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2006-3360
- ADVISORYhttps://security-tracker.debian.org/tracker/CVE-2006-3360
- PATCHhttps://github.com/phpsysinfo/phpsysinfo
- WEBhttps://exchange.xforce.ibmcloud.com/vulnerabilities/27527
- WEBhttps://github.com/phpsysinfo/phpsysinfo/commit/60b5bbb5d1cc17f44050e99a3e746f55a4fd4e18
- WEBhttps://github.com/phpsysinfo/phpsysinfo/issues/107
- WEBhttps://github.com/phpsysinfo/phpsysinfo/issues/368#issuecomment-1380842745