Multiple cross-site scripting (XSS) vulnerabilities in phpSysInfo 2.3, when registerglobals is enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) sensorprogram parameter to index.php, (2) text[language], (3) text[template], or (4) hidepicklist parameter to systemfooter.php.