20050323 [SECURITYREASON.COM] phpSysInfo 2.3 Multiple vulnerabilitiesmailing list
http://marc.info/?l=bugtraq&m=111161017209422&w=2 CVE-2005-0869
phpsysinfo phpsysinfo Exposure of Sensitive Information to an Unauthorized Actor
Record summary
CVE-2005-0869 has a selected CVSS score of 5.0.
Description
phpSysInfo 2.3 allows remote attackers to obtain sensitive information via a direct request to (1) class.OpenBSD.inc.php, (2) class.NetBSD.inc.php, (3) class.FreeBSD.inc.php, (4) class.Darwin.inc.php, (5) XPath.class.php, (6) system_header.php, or (7) system_footer.php, which reveal the path in a PHP error message.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jul 20, 2026 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
phpsysinfoBrowse phpsysinfo / phpsysinfo | VulnCheck | Version data not supplied | |
References
414690Third-party advisory
http://secunia.com/advisories/14690 phpsysinfo-path-disclosure(19808)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/19808 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2005-0869