![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
Test ID: | 1.3.6.1.4.1.25623.1.0.11229 |
Category: | Web application abuses |
Title: | phpinfo() Output Reporting (HTTP) |
Summary: | Reporting of files containing the output of the phpinfo() PHP; function previously detected via HTTP. |
Description: | Summary: Reporting of files containing the output of the phpinfo() PHP function previously detected via HTTP. Vulnerability Insight: Many PHP installation tutorials instruct the user to create a file called phpinfo.php or similar containing the phpinfo() statement. Such a file is often left back in the webserver directory. Vulnerability Impact: Some of the information that can be gathered from this file includes: The username of the user running the PHP process, if it is a sudo user, the IP address of the host, the web server version, the system version (Unix, Linux, Windows, ...), and the root directory of the web server. Affected Software/OS: All systems exposing a file containing the output of the phpinfo() PHP function. This VT is also reporting if an affected endpoint for the following products have been identified: - CVE-2008-0149: TUTOS - CVE-2023-49282, CVE-2023-49283: Microsoft Graph PHP SDK Solution: Delete the listed files or restrict access to them. CVSS Score: 5.0 CVSS Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N |
Cross-Ref: |
Common Vulnerability Exposure (CVE) ID: CVE-2008-0149 https://www.exploit-db.com/exploits/4861 http://secunia.com/advisories/28291 Common Vulnerability Exposure (CVE) ID: CVE-2023-49282 https://github.com/microsoftgraph/msgraph-beta-sdk-php/compare/2.0.0...2.0.1 https://github.com/microsoftgraph/msgraph-sdk-php-core/compare/2.0.1...2.0.2 https://github.com/microsoftgraph/msgraph-sdk-php/compare/1.109.0...1.109.1 https://github.com/microsoftgraph/msgraph-sdk-php/security/advisories/GHSA-cgwq-6prq-8h9q https://owncloud.com/security-advisories/disclosure-of-sensitive-credentials-and-configuration-in-containerized-deployments/ Common Vulnerability Exposure (CVE) ID: CVE-2023-49283 https://github.com/microsoftgraph/msgraph-sdk-php-core/security/advisories/GHSA-mhhp-c3cm-2r86 |
Copyright | Copyright (C) 2003 Randy Matz |
This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |