CVE Vulnerabilities

CVE-2005-0870

Published: May 02, 2005 | Modified: Jul 11, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
UNTRIAGED

Multiple cross-site scripting (XSS) vulnerabilities in phpSysInfo 2.3, when register_globals is enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) sensor_program parameter to index.php, (2) text[language], (3) text[template], or (4) hide_picklist parameter to system_footer.php.

Affected Software

Name Vendor Start Version End Version
Phpsysinfo Phpsysinfo 2.3 (including) 2.3 (including)
Egroupware Ubuntu dapper *
Egroupware Ubuntu devel *
Egroupware Ubuntu edgy *
Egroupware Ubuntu feisty *
Phpgroupware Ubuntu dapper *
Phpgroupware Ubuntu devel *
Phpgroupware Ubuntu edgy *
Phpgroupware Ubuntu feisty *
Phpsysinfo Ubuntu dapper *
Phpsysinfo Ubuntu devel *
Phpsysinfo Ubuntu edgy *
Phpsysinfo Ubuntu feisty *

References