Unrated severityNVD Advisory· Published May 2, 2005· Updated Apr 16, 2026
CVE-2005-0870
CVE-2005-0870
Description
Multiple cross-site scripting (XSS) vulnerabilities in phpSysInfo 2.3, when register_globals is enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) sensor_program parameter to index.php, (2) text[language], (3) text[template], or (4) hide_picklist parameter to system_footer.php.
Affected products
1- cpe:2.3:a:phpsysinfo:phpsysinfo:2.3:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
14- secunia.com/advisories/14690/nvdVendor Advisory
- bugs.debian.org/cgi-bin/bugreport.cginvd
- marc.infonvd
- secunia.com/advisories/17616nvd
- secunia.com/advisories/17643nvd
- www.debian.org/security/2005/dsa-724nvd
- www.debian.org/security/2005/dsa-897nvd
- www.debian.org/security/2005/dsa-898nvd
- www.debian.org/security/2005/dsa-899nvd
- www.mandriva.com/security/advisoriesnvd
- www.securityfocus.com/archive/1/416543nvd
- www.securityfocus.com/bid/12887nvd
- www.securityfocus.com/bid/15414nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/19807nvd
News mentions
0No linked articles in our index yet.