PT-2005-3836 · Php · Php Advanced Transfer Manager

Published

2005-09-20

·

Updated

2008-09-05

·

CVE-2005-2999

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions PHP Advanced Transfer Manager version 1.30
Description The issue allows remote attackers to obtain sensitive PHP configuration information. This is achieved by making a direct request to the "test.php" endpoint.
Recommendations For PHP Advanced Transfer Manager version 1.30, consider restricting access to the "test.php" endpoint to prevent unauthorized disclosure of sensitive information.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-2999

Affected Products

Php Advanced Transfer Manager