CVE-2006-3360
phpSysInfo allows remote attackers to determine the existence of arbitrary files via a .. (dot dot) sequence
EPSS 5.4%
描述
Directory traversal vulnerability in index.php in phpSysInfo 2.5.1 allows remote attackers to determine the existence of arbitrary files via a .. (dot dot) sequence and a trailing null (%00) byte in the lng parameter, which will display a different error message if the file exists.
如何修補 CVE-2006-3360
要修補 CVE-2006-3360,請將受影響套件升級到下列已修補版本。
- Debian/phpsysinfo—升級至 3.2.5-3 或更新版本
CVE-2006-3360 正在被利用嗎?
中等 — EPSS 為 5.4%,可持續追蹤但非最高優先。
受影響套件(1)
- from 0, < 3.2.5-3