Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
146377 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.11229
Categoría:Web application abuses
Título:phpinfo() Output Reporting (HTTP)
Resumen:Reporting of files containing the output of the phpinfo() PHP; function previously detected via HTTP.
Descripción:Summary:
Reporting of files containing the output of the phpinfo() PHP
function previously detected via HTTP.

Vulnerability Insight:
Many PHP installation tutorials instruct the user to create a
file called phpinfo.php or similar containing the phpinfo() statement. Such a file is often left
back in the webserver directory.

Vulnerability Impact:
Some of the information that can be gathered from this file
includes:

The username of the user running the PHP process, if it is a sudo user, the IP address of the
host, the web server version, the system version (Unix, Linux, Windows, ...), and the root
directory of the web server.

Affected Software/OS:
All systems exposing a file containing the output of the
phpinfo() PHP function.

This VT is also reporting if an affected endpoint for the following products have been identified:

- CVE-2008-0149: TUTOS

- CVE-2023-49282, CVE-2023-49283: Microsoft Graph PHP SDK

- CVE-2024-10486: Google for WooCommerce plugin for WordPress

Solution:
Delete the listed files or restrict access to them.

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:N/A:N

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2008-0149
https://www.exploit-db.com/exploits/4861
http://secunia.com/advisories/28291
Common Vulnerability Exposure (CVE) ID: CVE-2023-49282
https://github.com/microsoftgraph/msgraph-beta-sdk-php/compare/2.0.0...2.0.1
https://github.com/microsoftgraph/msgraph-sdk-php-core/compare/2.0.1...2.0.2
https://github.com/microsoftgraph/msgraph-sdk-php/compare/1.109.0...1.109.1
https://github.com/microsoftgraph/msgraph-sdk-php/security/advisories/GHSA-cgwq-6prq-8h9q
https://owncloud.com/security-advisories/disclosure-of-sensitive-credentials-and-configuration-in-containerized-deployments/
Common Vulnerability Exposure (CVE) ID: CVE-2023-49283
https://github.com/microsoftgraph/msgraph-sdk-php-core/security/advisories/GHSA-mhhp-c3cm-2r86
Common Vulnerability Exposure (CVE) ID: CVE-2024-10486
CopyrightCopyright (C) 2003 Randy Matz

Esta es sólo una de 146377 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.