{"id":"CVE-2005-4875","aliases":[],"url":"https://o3.security/vulnerability/CVE-2005-4875","summary":"TYPO3 Reveals Sensitive Information via Direct Request to `misc/phpcheck/`","details":"TYPO3 3.8.0 and earlier allows remote attackers to obtain sensitive information via a direct request to misc/phpcheck/, which invokes the phpinfo function and prints values of unspecified environment variables.","published":"2022-05-01T02:31:34Z","modified":"2025-04-04T14:57:08.485867Z","cvss":null,"epss":{"score":0.01382,"percentile":0.70808,"asOf":"2026-09-17"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"typo3/cms","fixedVersion":"3.8.1"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2005-4875"},{"type":"WEB","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/42457"},{"type":"PACKAGE","url":"https://github.com/TYPO3/typo3"},{"type":"WEB","url":"https://web.archive.org/web/20080228231555/http://typo3.org/teams/security/security-bulletins/typo3-20050725-1"},{"type":"WEB","url":"http://bugs.typo3.org/view.php?id=1250"},{"type":"WEB","url":"http://typo3.org/teams/security/security-bulletins/typo3-20050725-1"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2025-04-04T14:57:08.485867Z"}}