AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2005-3347

MEDIUM · CVSS 6.8 EPSS 3.55%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2005-11-18 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 6.8. It may be remotely exploitable.

CVE
CVE-2005-3347
Severity
MEDIUM
CVSS
6.8
EPSS
3.55%

Original NVD Description

Multiple directory traversal vulnerabilities in index.php in phpSysInfo 2.4 and earlier, as used in phpgroupware 0.9.16 and earlier, and egrouwpware before 1.0.0.009, allow remote attackers to include arbitrary files via .. (dot dot) sequences in the (1) sensor_program parameter or the (2) _SERVER[HTTP_ACCEPT_LANGUAGE] parameter, which overwrites an internal variable, a variant of CVE-2003-0536. NOTE: due to a typo in an advisory, an issue in osh was inadvertently linked to this identifier; the proper identifier for the osh issue is CVE-2005-3346.