CVE-2016-3124
published 2017-02-07CVE-2016-3124: The sanitycheck module in SimpleSAMLphp before 1.14.1 allows remote attackers to learn the PHP version on the system via unspecified vectors.
PriorityP428medium5.3CVSS 3.0
AVNACLPRNUINSUCLINAN
EPSS
1.34%
68.1th percentile
The sanitycheck module in SimpleSAMLphp before 1.14.1 allows remote attackers to learn the PHP version on the system via unspecified vectors.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | simplesamlphp | < simplesamlphp 1.14.1-1 (bookworm) | simplesamlphp 1.14.1-1 (bookworm) |
| simplesamlphp | simplesamlphp | <= 1.14.0 | — |
| simplesamlphp | simplesamlphp | >= 0 < 1.14.1-1 | 1.14.1-1 |
| simplesamlphp | simplesamlphp | >= 0 < 1.14.1-1 | 1.14.1-1 |
| simplesamlphp | simplesamlphp | >= 0 < 1.14.1 | 1.14.1 |
CVSS provenance
nvdv3.05.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv5.3MEDIUM
vendor_debian5.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
SimpleSAMLphp Information leakage issue in the sanitycheck module
osv·2022-05-14
CVE-2016-3124 [MEDIUM] SimpleSAMLphp Information leakage issue in the sanitycheck module
SimpleSAMLphp Information leakage issue in the sanitycheck module
The sanitycheck module in SimpleSAMLphp before 1.14.1 allows remote attackers to learn the PHP version on the system via unspecified vectors.
GHSA
SimpleSAMLphp Information leakage issue in the sanitycheck module
ghsa·2022-05-14
CVE-2016-3124 [MEDIUM] CWE-200 SimpleSAMLphp Information leakage issue in the sanitycheck module
SimpleSAMLphp Information leakage issue in the sanitycheck module
The sanitycheck module in SimpleSAMLphp before 1.14.1 allows remote attackers to learn the PHP version on the system via unspecified vectors.
OSV
CVE-2016-3124: The sanitycheck module in SimpleSAMLphp before 1
osv·2017-02-07·CVSS 5.3
CVE-2016-3124 [MEDIUM] CVE-2016-3124: The sanitycheck module in SimpleSAMLphp before 1
The sanitycheck module in SimpleSAMLphp before 1.14.1 allows remote attackers to learn the PHP version on the system via unspecified vectors.
Debian
CVE-2016-3124: simplesamlphp - The sanitycheck module in SimpleSAMLphp before 1.14.1 allows remote attackers to...
vendor_debian·2016·CVSS 5.3
CVE-2016-3124 [MEDIUM] CVE-2016-3124: simplesamlphp - The sanitycheck module in SimpleSAMLphp before 1.14.1 allows remote attackers to...
The sanitycheck module in SimpleSAMLphp before 1.14.1 allows remote attackers to learn the PHP version on the system via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 1.14.1-1)
bullseye: resolved (fixed in 1.14.1-1)
sid: resolved (fixed in 1.14.1-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2017-02-07
Published