CVE-2006-3360: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
(updated )
Directory traversal vulnerability in index.php in phpSysInfo allows remote attackers to determine the existence of arbitrary files via a .. (dot dot) sequence and a trailing null (%00) byte in the lng parameter, which will display a different error message if the file exists.
References
Detect and mitigate CVE-2006-3360 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →