CVE-2005-0870
egroupware - programming errors
EPSS 3.7%
Description
Multiple cross-site scripting (XSS) vulnerabilities in phpSysInfo 2.3, when register_globals is enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) sensor_program parameter to index.php, (2) text[language], (3) text[template], or (4) hide_picklist parameter to system_footer.php.
How to fix CVE-2005-0870
To remediate CVE-2005-0870, upgrade the affected package to a fixed version below.
- Debian/phpsysinfo—upgrade to 2.3-7 or later
Is CVE-2005-0870 being exploited?
Low — EPSS is 3.7%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 2.3-7