|
|
Info |
Last Modified |
| about 1 year ago |
|
|
|
|
|
Description |
phpSysInfo contains a flaw that allows a remote attacker to access arbitrary files outside of the web path. The issue is due to the index.php script not properly sanitizing user input, specifically directory traversal style attacks (../../) supplied via the 'lng' variable and null terminated.
|
|
Classification |
Location:
Remote/Network Access Required
Attack Type:
Information Disclosure,
Input Manipulation
Impact:
Loss of Confidentiality
Exploit:
Exploit Available
OSVDB:
Web Related
|
|
Solution |
Currently, there are no known upgrades, patches, or workarounds available to correct this issue.
|
|
Products |
|
phpSysInfo
 |
2.0 |
2.5.1 |
2.1 |
|
|
|
|
|
Credit |
- Micheal Turner - wh1t3h4t3yahoo.co.uk -
- Albert Puigsech Galicia - ripe
7a69ezine.org - Personal Page
|
|
BlogsProvided by Technorati
|
None found at this time
|
|
|