CVE Vulnerabilities

CVE-2007-4048

Published: Jul 30, 2007 | Modified: Oct 15, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
UNTRIAGED

Cross-site scripting (XSS) vulnerability in index.php in phpSysInfo 2.5.4-dev and earlier allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.

Affected Software

Name Vendor Start Version End Version
Phpsysinfo Phpsysinfo * 2.5.4-dev (including)
Egroupware Ubuntu dapper *
Egroupware Ubuntu devel *
Egroupware Ubuntu edgy *
Egroupware Ubuntu feisty *
Egroupware Ubuntu gutsy *
Egroupware Ubuntu hardy *
Egroupware Ubuntu intrepid *
Egroupware Ubuntu jaunty *
Egroupware Ubuntu karmic *
Phpgroupware Ubuntu dapper *
Phpgroupware Ubuntu devel *
Phpgroupware Ubuntu edgy *
Phpgroupware Ubuntu feisty *
Phpgroupware Ubuntu gutsy *
Phpgroupware Ubuntu hardy *
Phpgroupware Ubuntu intrepid *
Phpgroupware Ubuntu jaunty *
Phpgroupware Ubuntu karmic *
Phpsysinfo Ubuntu dapper *
Phpsysinfo Ubuntu devel *
Phpsysinfo Ubuntu edgy *
Phpsysinfo Ubuntu feisty *
Phpsysinfo Ubuntu gutsy *
Phpsysinfo Ubuntu hardy *
Phpsysinfo Ubuntu intrepid *
Phpsysinfo Ubuntu jaunty *
Phpsysinfo Ubuntu karmic *

References