4.3
CVSSv2

CVE-2005-3348

Published: 18/11/2005 Updated: 11/07/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

HTTP response splitting vulnerability in index.php in phpSysInfo 2.4 and previous versions, as used in phpgroupware 0.9.16 and previous versions, and egroupware prior to 1.0.0.009, allows remote malicious users to spoof web content and poison web caches via CRLF sequences in the charset parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

phpsysinfo phpsysinfo 2.3

phpsysinfo phpsysinfo 2.4

phpsysinfo phpsysinfo 2.0

phpsysinfo phpsysinfo 2.1

Vendor Advisories

Debian Bug report logs - #339079 CVE-2005-334[78]: Two vulnerabilities in phpsysinfo Package: phpsysinfo; Maintainer for phpsysinfo is Bjoern Boschman <bjoern@boschmande>; Source for phpsysinfo is src:phpsysinfo (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@inutilorg> Date: Mon, 14 Nov 2005 20:49:25 UT ...
Several vulnerabilities have been discovered in phpsysinfo, a PHP based host information application The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2005-0870 Maksymilian Arciemowicz discovered several cross site scripting problems, of which not all were fixed in DSA 724 CVE-2005-3347 Christop ...
Several vulnerabilities have been discovered in phpsysinfo, a PHP based host information application that is included in phpgroupware The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2005-0870 Maksymilian Arciemowicz discovered several cross site scripting problems, of which not all were fixed in ...
Several vulnerabilities have been discovered in egroupware, a web-based groupware suite The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2005-0870 Maksymilian Arciemowicz discovered several cross site scripting problems in phpsysinfo, which are also present in the imported version in egroupware a ...

Exploits

phpSysInfo versions 24 and below suffer from cross site scripting, HTTP response splitting, and arbitrary file inclusion flaws ...