Multiple Cross-Site Scripting Vulnerabilities in phpSysInfo by phpSysInfo Inc.
CVE-2005-0870
Currently unrated
What is CVE-2005-0870?
phpSysInfo 2.3 is vulnerable to multiple cross-site scripting (XSS) attacks when the register_globals directive is enabled. This vulnerability allows remote attackers to inject arbitrary web scripts or HTML into the application. The affected parameters include sensor_program in index.php and text[language], text[template], and hide_picklist in system_footer.php. Proper validation and sanitation of user inputs can mitigate this issue, but the risk of remote exploitation remains for installations with register_globals turned on.
