phpSysInfo Index.php Information Disclosure Vulnerability
BID:18868
CVE-2006-3360 |Info
phpSysInfo Index.php Information Disclosure Vulnerability
| Bugtraq ID: | 18868 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 06 2006 12:00AM |
| Updated: | Jul 06 2006 12:00AM |
| Credit: | Micheal Turner is credited with the discovery of this vulnerability. |
| Vulnerable: |
phpSysInfo phpSysInfo 2.5.1 |
| Not Vulnerable: | |
Discussion
phpSysInfo Index.php Information Disclosure Vulnerability
phpSysInfo is prone to an information-disclosure vulnerability because the application fails to properly sanitize user supplied input.
An attacker can exploit this vulnerability to gain access to potentially sensitive information that may aid them in further attacks.
phpSysInfo is prone to an information-disclosure vulnerability because the application fails to properly sanitize user supplied input.
An attacker can exploit this vulnerability to gain access to potentially sensitive information that may aid them in further attacks.
Exploit / POC
phpSysInfo Index.php Information Disclosure Vulnerability
This issue can be exploited through a web client.
This issue can be exploited through a web client.
Solution / Fix
phpSysInfo Index.php Information Disclosure Vulnerability
Solution:
The vendor has released a fix to address this issue.
Solution:
The vendor has released a fix to address this issue.