Vulnerabilities > CVE-2006-3360 - Unspecified vulnerability in PHPsysinfo
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Directory traversal vulnerability in index.php in phpSysInfo 2.5.1 allows remote attackers to determine the existence of arbitrary files via a .. (dot dot) sequence and a trailing null (%00) byte in the lng parameter, which will display a different error message if the file exists.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 5 |
References
- http://archives.neohapsis.com/archives/fulldisclosure/2006-07/0066.html
- http://archives.neohapsis.com/archives/fulldisclosure/2006-07/0065.html
- http://secunia.com/advisories/20939
- http://www.securityfocus.com/bid/18868
- http://securitytracker.com/id?1016440
- http://www.osvdb.org/27015
- http://www.vupen.com/english/advisories/2006/2668
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27527
- https://github.com/advisories/GHSA-2wxv-3g4v-p76p
- https://github.com/phpsysinfo/phpsysinfo/issues/368#issuecomment-1380842745