Name | CVE-2006-3360 |
Description | Directory traversal vulnerability in index.php in phpSysInfo 2.5.1 allows remote attackers to determine the existence of arbitrary files via a .. (dot dot) sequence and a trailing null (%00) byte in the lng parameter, which will display a different error message if the file exists. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
Vulnerable and fixed packages
The table below lists information on source packages.
Source Package | Release | Version | Status |
---|
phpsysinfo (PTS) | jessie | 3.0.17-1 | vulnerable |
| bullseye | 3.2.5-3 | fixed |
| bookworm | 3.4.2-3 | fixed |
| sid, trixie | 3.4.4-1 | fixed |
The information below is based on the following data on fixed versions.
Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
---|
egroupware | source | (unstable) | (unfixed) | unimportant | | |
phpgroupware | source | (unstable) | (unfixed) | unimportant | | |
phpsysinfo | source | (unstable) | 3.2.5-3 | unimportant | | |
Notes
https://github.com/phpsysinfo/phpsysinfo/commit/60b5bbb5d1cc17f44050e99a3e746f55a4fd4e18 (v3.2.5)
Only the existence of files inside the WWW root is leaked. If this is
a threat to your setup you most probably shouldn't install a script which
exposes all your system data, either.