Cross-site scripting (XSS) vulnerability in the phpinfo function in PHP 4.2.3 allows remote attackers to inject arbitrary web script or HTML via the query string argument, as demonstrated using soinfo.php.Referenceshttp://archives.neohapsis.com/archives/bugtraq/2003-06/0027.htmlhttp://archives.neohapsis.com/archives/vulnwatch/2002-q4/0021.htmlhttp://www.iss.net/security_center/static/10355.phphttp://www.techie.hopto.org/vulns/2002-36.txt