Directory Traversal Vulnerability in phpSysInfo by phpSysInfo
CVE-2006-3360

Currently unrated

Key Information:

Vendor

PHPsysinfo

Vendor
CVE Published:
6 July 2006

What is CVE-2006-3360?

A directory traversal vulnerability exists in index.php of phpSysInfo version 2.5.1, allowing remote attackers to exploit the lng parameter. By utilizing a '..' (dot dot) sequence accompanied by a trailing null byte (%00), an attacker could determine the existence of arbitrary files on the server. An error message would differ based on whether the targeted file exists, potentially leading to information disclosure and further exploitation.

References

EPSS Score

5% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.