Phpsysinfo is a lightweight system-information display utility with a narrow but notable deployment footprint across web-hosted monitoring and administration interfaces. Its vulnerability profile clusters around web-application attack surface: cross-site request forgery, path-traversal conditions, and input-validation weaknesses that reflect the product's role as a public-facing information disclosure tool frequently acquire public exploit code. Defenders should treat instances of this utility as sensitive monitoring infrastructure and restrict access through authentication, network segmentation, or removal where feasible; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Phpsysinfo over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2005-0870MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in phpSysInfo 2.3, when register_globals is enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) s | May 2, 2005 | 4.3 | 22 | NO | YES |
Directory traversal vulnerability in phpSysInfo 2.1 and earlier allows attackers with write access to a local directory to read arbitrary files as the PHP user or cause a denial of | Aug 18, 2003 | 3.6 | 20 | NO | YES |
CVE-2023-49006MEDIUM Cross Site Request Forgery (CSRF) vulnerability in Phpsysinfo version 3.4.3 allows a remote attacker to obtain sensitive information via a crafted page in the XML.php file. | Dec 19, 2023 | 6.5 | 19 | NO | NO |
CVE-2006-3360MEDIUM Directory traversal vulnerability in index.php in phpSysInfo 2.5.1 allows remote attackers to determine the existence of arbitrary files via a .. (dot dot) sequence and a trailing | Jul 6, 2006 | 5.0 | 19 | NO | NO |
CVE-2005-0869MEDIUM phpSysInfo 2.3 allows remote attackers to obtain sensitive information via a direct request to (1) class.OpenBSD.inc.php, (2) class.NetBSD.inc.php, (3) class.FreeBSD.inc.php, (4) c | May 2, 2005 | 5.0 | 16 | NO | NO |
CVE-2007-4048MEDIUM Cross-site scripting (XSS) vulnerability in index.php in phpSysInfo 2.5.4-dev and earlier allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO. | Jul 30, 2007 | 4.3 | 14 | NO | NO |
CVE-2005-3348MEDIUM HTTP response splitting vulnerability in index.php in phpSysInfo 2.4 and earlier, as used in phpgroupware 0.9.16 and earlier, and egroupware before 1.0.0.009, allows remote attacke | Nov 18, 2005 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Phpsysinfo.
Media articles that mention a CVE ID that affects a product developed by Phpsysinfo — matched by CVE ID, not by vendor name.