about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , PHPsysInfo Multiple Input Validation Vulnerabilities


Title PHPsysInfo Multiple Input Validation Vulnerabilities
Published 2005-11-14-12:00AM
Updated 2005-11-23-04:47PM
Class Input Validation Error
CVE   CVE-2005-3347 CVE-2005-3348 CVE-2003-0536
Remote  Yes
Local  No
Credit  The vendor disclosed these vulnerabilities.
Vulnerable  phpSysInfo phpSysInfo 2.4
phpSysInfo phpSysInfo 2.3
phpSysInfo phpSysInfo 2.1
phpSysInfo phpSysInfo 2.0
Debian Linux 3.0
Debian Linux 3.0 alpha
Debian Linux 3.0 arm
Debian Linux 3.0 hppa
Debian Linux 3.0 ia32
Debian Linux 3.0 ia64
Debian Linux 3.0 m68k
Debian Linux 3.0 mips
Debian Linux 3.0 mipsel
Debian Linux 3.0 ppc
Debian Linux 3.0 s/390
Debian Linux 3.0 sparc
MandrakeSoft Corporate Server 3.0 x86_64
MandrakeSoft Corporate Server 3.0
Gentoo Linux
eGroupWare eGroupWare 1.0 .0.007
Debian Linux 3.1
Debian Linux 3.1 alpha
Debian Linux 3.1 amd64
Debian Linux 3.1 arm
Debian Linux 3.1 hppa
Debian Linux 3.1 ia32
Debian Linux 3.1 ia64
Debian Linux 3.1 m68k
Debian Linux 3.1 mips
Debian Linux 3.1 mipsel
Debian Linux 3.1 ppc
Debian Linux 3.1 s/390
Debian Linux 3.1 sparc
Gentoo Linux
Debian Linux 3.1 sparc
Debian Linux 3.1 s/390
Debian Linux 3.1 ppc
Debian Linux 3.1 mipsel
Debian Linux 3.1 mips
Debian Linux 3.1 m68k
Debian Linux 3.1 ia64
Debian Linux 3.1 ia32
Debian Linux 3.1 hppa
Debian Linux 3.1 arm
Debian Linux 3.1 amd64
Debian Linux 3.1 alpha
Debian Linux 3.1
Debian Linux 3.0 sparc
Debian Linux 3.0 s/390
Debian Linux 3.0 ppc
Debian Linux 3.0 mipsel
Debian Linux 3.0 mips
Debian Linux 3.0 m68k
Debian Linux 3.0 ia64
Debian Linux 3.0 ia32
Debian Linux 3.0 hppa
Debian Linux 3.0 arm
Debian Linux 3.0 alpha
Debian Linux 3.0
Not Vulnerable  phpSysInfo phpSysInfo 2.4.1
Code   No exploit is required.

Example URI have been provided:

http://www.example.com/index.php?_SERVER[HTTP_ACCEPT_LANGUAGE]=../../README%00
http://www.example.com/index.php?_SERVER[HTTP_ACCEPT_LANGUAGE]=../../README%00&lng=../../README%00

http://www.example.com/index.php?sensor_program=lmsensors.inc.php/../../README%00

http://www.example.com/index.php?VERSION=%22%3E%3Cscript%3Ealert('xss')%3C/script%3E
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Fri, 18 Dec 2009 01:40:53 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
21420 www.peykn. whitesnake CMS is Fre sex actors news for c fotoya man tyturtr php-fusion shop581335 xaclass.co Shop Cart Php-Nuke e news for c maxcpm.inf www.kongqi components www.i5up.c www.minidi 0fly.cn www.terb&a Php-Nuke e taixiangqu home.77yoy Sri lanka exploit nu index.php? www.chinax news for c party sex shakira so PHP Advanc asairstarn 51-sf.com phpBB por Artis hot www.Soon 1 port 1104 Php-Nuke e BOTS blog.jshuw 2.6.17-1.2 phpBB por www.BSnude rasha 200 /compo lo172l www.xiaopi Play Video news for c