// For flags

CVE-2016-6639

 

Severity Score

7.5
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Cloud Foundry PHP Buildpack (aka php-buildpack) before 4.3.18 and PHP Buildpack Cf-release before 242, as used in Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.6.38 and 1.7.x before 1.7.19 and other products, place the .profile file in the htdocs directory, which might allow remote attackers to obtain sensitive information via an HTTP GET request for this file.

Cloud Foundry PHP Buildpack (también conocido como php-buildpack) en versiones anteriores a 4.3.18 y PHP Buildpack Cf-release en versiones anteriores a 242, como se usa en Pivotal Cloud Foundry (PCF) Elastic Runtime en versiones anteriores a 1.6.38 y 1.7.x en versiones anteriores a 1.7.19 y otros productos, sitúa el archivo .profile en el directorio htdocs, lo que podría permitir a atacantes remotos obtener información sensible a través de una petición HTTP GET para este archivo.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2016-08-10 CVE Reserved
  • 2016-09-18 CVE Published
  • 2023-03-07 EPSS Updated
  • 2024-08-06 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-254: 7PK - Security Features
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Cloudfoundry
Search vendor "Cloudfoundry"
Php-buildpack
Search vendor "Cloudfoundry" for product "Php-buildpack"
<= 4.3.17
Search vendor "Cloudfoundry" for product "Php-buildpack" and version " <= 4.3.17"
-
Affected
Pivotal
Search vendor "Pivotal"
Cloud Foundry Elastic Runtime
Search vendor "Pivotal" for product "Cloud Foundry Elastic Runtime"
<= 1.6.37
Search vendor "Pivotal" for product "Cloud Foundry Elastic Runtime" and version " <= 1.6.37"
-
Affected
Pivotal
Search vendor "Pivotal"
Cloud Foundry Elastic Runtime
Search vendor "Pivotal" for product "Cloud Foundry Elastic Runtime"
1.7.0
Search vendor "Pivotal" for product "Cloud Foundry Elastic Runtime" and version "1.7.0"
-
Affected
Pivotal
Search vendor "Pivotal"
Cloud Foundry Elastic Runtime
Search vendor "Pivotal" for product "Cloud Foundry Elastic Runtime"
1.7.1
Search vendor "Pivotal" for product "Cloud Foundry Elastic Runtime" and version "1.7.1"
-
Affected
Pivotal
Search vendor "Pivotal"
Cloud Foundry Elastic Runtime
Search vendor "Pivotal" for product "Cloud Foundry Elastic Runtime"
1.7.2
Search vendor "Pivotal" for product "Cloud Foundry Elastic Runtime" and version "1.7.2"
-
Affected
Pivotal
Search vendor "Pivotal"
Cloud Foundry Elastic Runtime
Search vendor "Pivotal" for product "Cloud Foundry Elastic Runtime"
1.7.3
Search vendor "Pivotal" for product "Cloud Foundry Elastic Runtime" and version "1.7.3"
-
Affected
Pivotal
Search vendor "Pivotal"
Cloud Foundry Elastic Runtime
Search vendor "Pivotal" for product "Cloud Foundry Elastic Runtime"
1.7.4
Search vendor "Pivotal" for product "Cloud Foundry Elastic Runtime" and version "1.7.4"
-
Affected
Pivotal
Search vendor "Pivotal"
Cloud Foundry Elastic Runtime
Search vendor "Pivotal" for product "Cloud Foundry Elastic Runtime"
1.7.5
Search vendor "Pivotal" for product "Cloud Foundry Elastic Runtime" and version "1.7.5"
-
Affected
Pivotal
Search vendor "Pivotal"
Cloud Foundry Elastic Runtime
Search vendor "Pivotal" for product "Cloud Foundry Elastic Runtime"
1.7.6
Search vendor "Pivotal" for product "Cloud Foundry Elastic Runtime" and version "1.7.6"
-
Affected
Pivotal
Search vendor "Pivotal"
Cloud Foundry Elastic Runtime
Search vendor "Pivotal" for product "Cloud Foundry Elastic Runtime"
1.7.7
Search vendor "Pivotal" for product "Cloud Foundry Elastic Runtime" and version "1.7.7"
-
Affected
Pivotal
Search vendor "Pivotal"
Cloud Foundry Elastic Runtime
Search vendor "Pivotal" for product "Cloud Foundry Elastic Runtime"
1.7.8
Search vendor "Pivotal" for product "Cloud Foundry Elastic Runtime" and version "1.7.8"
-
Affected
Pivotal
Search vendor "Pivotal"
Cloud Foundry Elastic Runtime
Search vendor "Pivotal" for product "Cloud Foundry Elastic Runtime"
1.7.9
Search vendor "Pivotal" for product "Cloud Foundry Elastic Runtime" and version "1.7.9"
-
Affected
Pivotal
Search vendor "Pivotal"
Cloud Foundry Elastic Runtime
Search vendor "Pivotal" for product "Cloud Foundry Elastic Runtime"
1.7.10
Search vendor "Pivotal" for product "Cloud Foundry Elastic Runtime" and version "1.7.10"
-
Affected
Pivotal
Search vendor "Pivotal"
Cloud Foundry Elastic Runtime
Search vendor "Pivotal" for product "Cloud Foundry Elastic Runtime"
1.7.11
Search vendor "Pivotal" for product "Cloud Foundry Elastic Runtime" and version "1.7.11"
-
Affected
Pivotal
Search vendor "Pivotal"
Cloud Foundry Elastic Runtime
Search vendor "Pivotal" for product "Cloud Foundry Elastic Runtime"
1.7.12
Search vendor "Pivotal" for product "Cloud Foundry Elastic Runtime" and version "1.7.12"
-
Affected
Pivotal
Search vendor "Pivotal"
Cloud Foundry Elastic Runtime
Search vendor "Pivotal" for product "Cloud Foundry Elastic Runtime"
1.7.13
Search vendor "Pivotal" for product "Cloud Foundry Elastic Runtime" and version "1.7.13"
-
Affected
Pivotal
Search vendor "Pivotal"
Cloud Foundry Elastic Runtime
Search vendor "Pivotal" for product "Cloud Foundry Elastic Runtime"
1.7.14
Search vendor "Pivotal" for product "Cloud Foundry Elastic Runtime" and version "1.7.14"
-
Affected
Pivotal
Search vendor "Pivotal"
Cloud Foundry Elastic Runtime
Search vendor "Pivotal" for product "Cloud Foundry Elastic Runtime"
1.7.15
Search vendor "Pivotal" for product "Cloud Foundry Elastic Runtime" and version "1.7.15"
-
Affected
Pivotal
Search vendor "Pivotal"
Cloud Foundry Elastic Runtime
Search vendor "Pivotal" for product "Cloud Foundry Elastic Runtime"
1.7.16
Search vendor "Pivotal" for product "Cloud Foundry Elastic Runtime" and version "1.7.16"
-
Affected
Pivotal
Search vendor "Pivotal"
Cloud Foundry Elastic Runtime
Search vendor "Pivotal" for product "Cloud Foundry Elastic Runtime"
1.7.17
Search vendor "Pivotal" for product "Cloud Foundry Elastic Runtime" and version "1.7.17"
-
Affected
Pivotal
Search vendor "Pivotal"
Cloud Foundry Elastic Runtime
Search vendor "Pivotal" for product "Cloud Foundry Elastic Runtime"
1.7.18
Search vendor "Pivotal" for product "Cloud Foundry Elastic Runtime" and version "1.7.18"
-
Affected