Multiple Cross-Site Scripting Vulnerabilities in phpSysInfo by phpSysInfo Inc.
CVE-2005-0870

Currently unrated

Key Information:

Vendor

PHPsysinfo

Vendor
CVE Published:
2 May 2005

What is CVE-2005-0870?

phpSysInfo 2.3 is vulnerable to multiple cross-site scripting (XSS) attacks when the register_globals directive is enabled. This vulnerability allows remote attackers to inject arbitrary web scripts or HTML into the application. The affected parameters include sensor_program in index.php and text[language], text[template], and hide_picklist in system_footer.php. Proper validation and sanitation of user inputs can mitigate this issue, but the risk of remote exploitation remains for installations with register_globals turned on.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.