CVE Database
/

CVE-2005-3347

Back to search

CVE-2005-3347

Published: Nov 18, 2005

Modified: Aug 7, 2024

PUBLISHED

Description

Multiple directory traversal vulnerabilities in index.php in phpSysInfo 2.4 and earlier, as used in phpgroupware 0.9.16 and earlier, and egrouwpware before 1.0.0.009, allow remote attackers to include arbitrary files via .. (dot dot) sequences in the (1) sensor_program parameter or the (2) _SERVER[HTTP_ACCEPT_LANGUAGE] parameter, which overwrites an internal variable, a variant of CVE-2003-0536. NOTE: due to a typo in an advisory, an issue in osh was inadvertently linked to this identifier; the proper identifier for the osh issue is CVE-2005-3346.

VendorProductVersions

n/a

n/a

affected
n/a

References

17616
third-party-advisory
x_refsource_SECUNIA
MDKSA-2005:212
vendor-advisory
x_refsource_MANDRIVA
15396
vdb-entry
x_refsource_BID
GLSA-200511-18
vendor-advisory
x_refsource_GENTOO
15414
vdb-entry
x_refsource_BID
17698
third-party-advisory
x_refsource_SECUNIA
DSA-898
vendor-advisory
x_refsource_DEBIAN
17441
third-party-advisory
x_refsource_SECUNIA
DSA-897
vendor-advisory
x_refsource_DEBIAN
17620
third-party-advisory
x_refsource_SECUNIA
17584
third-party-advisory
x_refsource_SECUNIA
17570
third-party-advisory
x_refsource_SECUNIA
DSA-899
vendor-advisory
x_refsource_DEBIAN
17643
third-party-advisory
x_refsource_SECUNIA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now