漏洞信息详情
PHPsysInfo多个输入确认漏洞
- CNNVD编号:CNNVD-200308-082
- 危害等级: 低危
- CVE编号:
CVE-2003-0536
- 漏洞类型:
路径遍历
- 发布时间:
2003-08-18
- 威胁类型:
本地
- 更新时间:
2005-10-20
- 厂 商:
phpsysinfo - 漏洞来源:
The vendor disclos… -
漏洞简介
phpSysInfo 2.1版本及之前版本存在目录遍历漏洞。带有本地目录写使用权的攻击者可以借助(1)模板或(2)lng参数中的..(点 点)序列像PHP用户读取任意文件或者导致服务拒绝。
漏洞公告
These vulnerabilities have been fixed in the 2.4.1 release of phpSysinfo. Please see the referenced advisories for further information.
eGroupWare eGroupWare 1.0 .0.007
-
Debian egroupware-addressbook_1.0.0.007-2.dfsg-2sarge4_all.debDebian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/e/egroupware/egroupware-a
ddressbook_1.0.0.007-2.dfsg-2sarge4_all.deb -
Debian egroupware-bookmarks_1.0.0.007-2.dfsg-2sarge4_all.debDebian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/e/egroupware/egroupware-b
ookmarks_1.0.0.007-2.dfsg-2sarge4_all.deb -
Debian egroupware-calendar_1.0.0.007-2.dfsg-2sarge4_all.debDebian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/e/egroupware/egroupware-c
alendar_1.0.0.007-2.dfsg-2sarge4_all.deb -
Debian egroupware-comic_1.0.0.007-2.dfsg-2sarge4_all.debDebian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/e/egroupware/egroupware-c
omic_1.0.0.007-2.dfsg-2sarge4_all.deb -
Debian egroupware-core_1.0.0.007-2.dfsg-2sarge4_all.debDebian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/e/egroupware/egroupware-c
ore_1.0.0.007-2.dfsg-2sarge4_all.deb -
Debian egroupware-developer-tools_1.0.0.007-2.dfsg-2sarge4_all.debDebian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/e/egroupware/egroupware-d
eveloper-tools_1.0.0.007-2.dfsg-2sarge4_all.deb -
Debian egroupware-email_1.0.0.007-2.dfsg-2sarge4_all.debDebian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/e/egroupware/egroupware-e
mail_1.0.0.007-2.dfsg-2sarge4_all.deb -
Debian egroupware-emailadmin_1.0.0.007-2.dfsg-2sarge4_all.debDebian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/e/egroupware/egroupware-e
mailadmin_1.0.0.007-2.dfsg-2sarge4_all.deb -
Debian egroupware-etemplate_1.0.0.007-2.dfsg-2sarge4_all.debDebian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/e/egroupware/egroupware-e
template_1.0.0.007-2.dfsg-2sarge4_all.deb -
Debian egroupware-felamimail_1.0.0.007-2.dfsg-2sarge4_all.debDebian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/e/egroupware/egroupware-f
elamimail_1.0.0.007-2.dfsg-2sarge4_all.deb -
Debian egroupware-filemanager_1.0.0.007-2.dfsg-2sarge4_all.debDebian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/e/egroupware/egroupware-f
ilemanager_1.0.0.007-2.dfsg-2sarge4_all.deb -
Debian egroupware-forum_1.0.0.007-2.dfsg-2sarge4_all.debDebian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/e/egroupware/egroupware-f
orum_1.0.0.007-2.dfsg-2sarge4_all.deb -
Debian egroupware-ftp_1.0.0.007-2.dfsg-2sarge4_all.debDebian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/e/egroupware/egroupware-f
tp_1.0.0.007-2.dfsg-2sarge4_all.deb -
Debian egroupware-fudforum_1.0.0.007-2.dfsg-2sarge4_all.debDebian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/e/egroupware/egroupware-f
udforum_1.0.0.007-2.dfsg-2sarge4_all.deb -
Debian egroupware-headlines_1.0.0.007-2.dfsg-2sarge4_all.debDebian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/e/egroupware/egroupware-h
eadlines_1.0.0.007-2.dfsg-2sarge4_all.deb -
Debian egroupware-infolog_1.0.0.007-2.dfsg-2sarge4_all.debDebian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/e/egroupware/egroupware-i
nfolog_1.0.0.007-2.dfsg-2sarge4_all.deb -
Debian egroupware-jinn_1.0.0.007-2.dfsg-2sarge4_all.debDebian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/e/egroupware/egroupware-j
inn_1.0.0.007-2.dfsg-2sarge4_all.deb -
Debian egroupware-ldap_1.0.0.007-2.dfsg-2sarge4_all.debDebian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/e/egroupware/egroupware-l
dap_1.0.0.007-2.dfsg-2sarge4_all.deb -
Debian egroupware-manual_1.0.0.007-2.dfsg-2sarge4_all.debDebian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/e/egroupware/egroupware-m
anual_1.0.0.007-2.dfsg-2sarge4_all.deb -
Debian egroupware-messenger_1.0.0.007-2.dfsg-2sarge4_all.debDebian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/e/egroupware/egroupware-m
essenger_1.0.0.007-2.dfsg-2sarge4_all.deb -
Debian egroupware-news-admin_1.0.0.007-2.dfsg-2sarge4_all.debDebian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/e/egroupware/egroupware-n
ews-admin_1.0.0.007-2.dfsg-2sarge4_all.deb -
Debian egroupware-phpbrain_1.0.0.007-2.dfsg-2sarge4_all.debDebian GNU/Linux 3.1 alias sarge
http
参考网址
来源: DEBIAN
名称: DSA-346
链接:http://www.debian.org/security/2003/dsa-346
来源: BUGTRAQ
名称: 20030425 Unauthorized reading files on phpSysInfo
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=105128606513226&w=2
来源: sourceforge.net
链接:http://sourceforge.net/tracker/index.php?func=detail&aid=670222&group_id=15&atid=100015
© 版权声明
文章版权归作者所有,未经允许请勿转载。
THE END