{"id":"CVE-2007-4048","details":"Cross-site scripting (XSS) vulnerability in index.php in phpSysInfo 2.5.4-dev and earlier allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.","modified":"2026-04-10T03:39:02.091954Z","published":"2007-07-30T16:30:00Z","references":[{"type":"ADVISORY","url":"http://secunia.com/advisories/26248"},{"type":"ADVISORY","url":"http://secunia.com/advisories/26473"},{"type":"WEB","url":"http://download.phpgroupware.org/"},{"type":"WEB","url":"http://osvdb.org/36601"},{"type":"WEB","url":"http://securityreason.com/securityalert/2952"},{"type":"WEB","url":"http://sourceforge.net/project/shownotes.php?release_id=532143"},{"type":"WEB","url":"http://www.securityfocus.com/archive/1/474756/100/0/threaded"},{"type":"WEB","url":"http://www.securityfocus.com/bid/25090"}],"schema_version":"1.7.5"}