Summary
The remote host is missing updates announced in
advisory GLSA 200511-18.
Solution
All phpSysInfo users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose '>=www-apps/phpsysinfo-2.4.1'
http://www.securityspace.com/smysecure/catid.html?in=GLSA%20200511-18 http://bugs.gentoo.org/show_bug.cgi?id=112482
http://www.hardened-php.net/advisory_222005.81.html
Insight
phpSysInfo is vulnerable to multiple issues, including a local file inclusion leading to information disclosure and the potential execution of arbitrary code.
Severity
Classification
-
CVE CVE-2005-3347, CVE-2005-3348 -
CVSS Base Score: 6.8
AV:N/AC:M/Au:N/C:P/I:P/A:P
Related Vulnerabilities