Cross-Site Scripting Vulnerability in phpSysInfo by phpGroupWare
CVE-2007-4048

Currently unrated

Key Information:

Vendor

PHPsysinfo

Vendor
CVE Published:
30 July 2007

What is CVE-2007-4048?

A cross-site scripting (XSS) vulnerability exists in the index.php file of phpSysInfo versions 2.5.4-dev and earlier. This flaw enables remote attackers to inject arbitrary web scripts or HTML into web pages viewed by users. The vulnerability arises through unsanitized input via the PATH_INFO variable, which can be exploited to execute harmful scripts in the context of the user's session. This poses significant security risks as it may compromise user data and allow unauthorized actions on behalf of users.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.