Vulnerabilities > CVE-2008-0149 - Unspecified vulnerability in Tutos 1.3

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
tutos
exploit available

Summary

TUTOS 1.3 allows remote attackers to read system information via a direct request to php/admin/phpinfo.php, which calls the phpinfo function.

Vulnerable Configurations

Part Description Count
Application
Tutos
1

Exploit-Db

descriptionTUTOS 1.3 (cmd.php) Remote Command Execution Vulnerability. CVE-2008-0148,CVE-2008-0149. Webapps exploit for php platform
fileexploits/php/webapps/4861.txt
idEDB-ID:4861
last seen2016-01-31
modified2008-01-07
platformphp
port
published2008-01-07
reporterHoussamix
sourcehttps://www.exploit-db.com/download/4861/
titleTUTOS 1.3 cmd.php Remote Command Execution Vulnerability
typewebapps