{"id":"GHSA-xj84-6q8f-qg2r","summary":"TYPO3 Reveals Sensitive Information via Direct Request to `misc/phpcheck/`","details":"TYPO3 3.8.0 and earlier allows remote attackers to obtain sensitive information via a direct request to misc/phpcheck/, which invokes the phpinfo function and prints values of unspecified environment variables.","aliases":["CVE-2005-4875"],"modified":"2025-04-04T14:57:08.485867Z","published":"2022-05-01T02:31:34Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2025-04-04T14:15:55Z","nvd_published_at":"2005-12-31T05:00:00Z","cwe_ids":["CWE-200"],"severity":"HIGH"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2005-4875"},{"type":"WEB","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/42457"},{"type":"PACKAGE","url":"https://github.com/TYPO3/typo3"},{"type":"WEB","url":"https://web.archive.org/web/20080228231555/http://typo3.org/teams/security/security-bulletins/typo3-20050725-1"},{"type":"WEB","url":"http://bugs.typo3.org/view.php?id=1250"},{"type":"WEB","url":"http://typo3.org/teams/security/security-bulletins/typo3-20050725-1"}],"affected":[{"package":{"name":"typo3/cms","ecosystem":"Packagist","purl":"pkg:composer/typo3/cms"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.8.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-xj84-6q8f-qg2r/GHSA-xj84-6q8f-qg2r.json"}}],"schema_version":"1.9.0"}