phpSysInfo allows remote attackers to determine the existence of arbitrary files via a .. (dot dot) sequence

Description

Directory traversal vulnerability in index.php in phpSysInfo prior to 3.2.5 allows remote attackers to determine the existence of arbitrary files via a .. (dot dot) sequence and a trailing null (%00) byte in the lng parameter, which will display a different error message if the file exists.

Basic information

Type
reviewed
Severity
medium
Advisory on GitHub
Open advisory ↗
Repository advisory
Source code
Browse source ↗
Published (advisory)
2022-05-01 07:08:17 UTC
Updated
2023-03-30 20:57:09 UTC
GitHub reviewed
2023-03-30 20:57:08 UTC
NVD published
2006-07-06

EPSS Score

Score Percentile
7.87% 91.99%

CVSS Scores

No CVSS scores in this advisory.

Identifiers

CWEs

CWE id Name
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Affected packages (1)

Vulnerable version ranges and first patched releases as published by GitHub.

Ecosystem Package Vulnerable range First patched Vulnerable functions
composer phpsysinfo/phpsysinfo < 3.2.5 3.2.5

References

cvelogic Threat Intelligence