Mailing the story:

Debian alert: New phpsysinfo packages fix directory traversal

  • Mailing list (Posted by on CST)
  • Story Type: Security; Groups: Debian
Albert Puigsech Galicia <ripe@7a69ezine.org> reported that phpsysinfo, a web-based program to display status information about the system, contains two vulnerabilities which could allow local files to be read, or arbitrary PHP code to be executed, under the privileges of the web server process (usually www-data). These vulnerabilities require access to a writable directory on the system in order to be exploited.
What is your name?

What is your E-Mail address?

What is the email address of the recipient?

Add a special note from yourself?