Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
phpgroupware phpgroupware 0.9.16.000 vulnerabilities and exploits
(subscribe to this query)
435
VMScore
CVE-2004-2574
Cross-site scripting (XSS) vulnerability in index.php in phpGroupWare 0.9.14.005 and previous versions allows remote malicious users to inject arbitrary web script or HTML via the date parameter in a calendar.uicalendar.planner menuaction.
Phpgroupware Phpgroupware 0.9.16.000
Phpgroupware Phpgroupware 0.9.16.002
Phpgroupware Phpgroupware 0.9.16.003
Phpgroupware Phpgroupware
1 EDB exploit
445
VMScore
CVE-2004-2575
phpGroupWare 0.9.14.005 and previous versions allow remote malicious users to obtain sensitive information via a direct request to (1) hook_admin.inc.php, (2) hook_home.inc.php, (3) class.holidaycalc.inc.php, and (4) setup.inc.php.sample, which reveals the path in an error messag...
Phpgroupware Phpgroupware 0.9.16.002
Phpgroupware Phpgroupware 0.9.16.005
Phpgroupware Phpgroupware 0.9.16.000
Phpgroupware Phpgroupware 0.9.16.003
383
VMScore
CVE-2005-2761
Cross-site scripting (XSS) vulnerability in phpGroupWare 0.9.16.000 allows administrators to inject arbitrary web script or HTML by modifying the main screen message.
Phpgroupware Phpgroupware 0.9.16.000
445
VMScore
CVE-2004-2576
class.vfs_dav.inc.php in phpGroupWare 0.9.16.000 does not create .htaccess files to enable authorization checks for access to users' home-directory files, which allows remote malicious users to obtain sensitive information from these files.
Phpgroupware Phpgroupware 0.9.16.000
605
VMScore
CVE-2004-0875
Multiple cross-site scripting (XSS) vulnerabilities in Phpgroupware (aka webdistro) 0.9.16.002 and previous versions allow remote malicious users to insert arbitrary HTML or web script, as demonstrated with a request to the wiki module.
Phpgroupware Phpgroupware 0.9.14.005
Phpgroupware Phpgroupware 0.9.14.006
Phpgroupware Phpgroupware 0.9.12
Phpgroupware Phpgroupware 0.9.13
Phpgroupware Phpgroupware 0.9.14.003
Phpgroupware Phpgroupware 0.9.14.007
Phpgroupware Phpgroupware 0.9.16.000
Phpgroupware Phpgroupware 0.9.16.002
Phpgroupware Phpgroupware 0.9.16 Rc1
605
VMScore
CVE-2010-0403
Directory traversal vulnerability in about.php in phpGroupWare (phpgw) prior to 0.9.16.016 allows remote malicious users to include and execute arbitrary local files via a .. (dot dot) in the app parameter.
Phpgroupware Phpgroupware 0.9.16.014
Phpgroupware Phpgroupware 0.9.16.012
Phpgroupware Phpgroupware 0.9.16.005
Phpgroupware Phpgroupware 0.9.16.003
Phpgroupware Phpgroupware 0.9.16.011
Phpgroupware Phpgroupware 0.9.16.010
Phpgroupware Phpgroupware
Phpgroupware Phpgroupware 0.9.16.002
Phpgroupware Phpgroupware 0.9.16.001
Phpgroupware Phpgroupware 0.9.16.000
Phpgroupware Phpgroupware 0.9.16
668
VMScore
CVE-2010-0404
Multiple SQL injection vulnerabilities in phpGroupWare (phpgw) prior to 0.9.16.016 allow remote malicious users to execute arbitrary SQL commands via unspecified parameters to (1) class.sessions_db.inc.php, (2) class.translation_sql.inc.php, or (3) class.auth_sql.inc.php in phpgw...
Phpgroupware Phpgroupware 0.9.16.014
Phpgroupware Phpgroupware 0.9.16.012
Phpgroupware Phpgroupware 0.9.16.011
Phpgroupware Phpgroupware 0.9.16
Phpgroupware Phpgroupware
Phpgroupware Phpgroupware 0.9.16.001
Phpgroupware Phpgroupware 0.9.16.000
Phpgroupware Phpgroupware 0.9.16.010
Phpgroupware Phpgroupware 0.9.16.005
Phpgroupware Phpgroupware 0.9.16.003
Phpgroupware Phpgroupware 0.9.16.002
505
VMScore
CVE-2004-1385
phpGroupWare 0.9.16.003 and previous versions allows remote malicious users to gain sensitive information via (1) unexpected characters in the session ID such as shell metacharacters, (2) an invalid appname parameter to preferences.php or (3) an invalid menuaction parameter to in...
Phpgroupware Phpgroupware 0.9.16.000
Phpgroupware Phpgroupware 0.9.16.002
Phpgroupware Phpgroupware 0.9.14.003
Phpgroupware Phpgroupware 0.9.14.005
Phpgroupware Phpgroupware 0.9.14.006
Phpgroupware Phpgroupware 0.9.14.007
Phpgroupware Phpgroupware 0.9.12
Phpgroupware Phpgroupware 0.9.13
Phpgroupware Phpgroupware 0.9.14
Phpgroupware Phpgroupware 0.9.16.003
Phpgroupware Phpgroupware 0.9.16 Rc1
1 EDB exploit
440
VMScore
CVE-2004-1384
Multiple cross-site scripting (XSS) vulnerabilities in phpGroupWare 0.9.16.003 and previous versions allow remote malicious users to inject arbitrary web script or HTML via the (1) kp3, (2) type, (3) msg, (4) forum_id, (5) pos, (6) cats_app, (7) cat_id, (8) msgball[msgnum], (9) f...
Phpgroupware Phpgroupware 0.9.14
Phpgroupware Phpgroupware 0.9.14.003
Phpgroupware Phpgroupware 0.9.16 Rc1
Phpgroupware Phpgroupware 0.9.14.007
Phpgroupware Phpgroupware 0.9.16.000
Phpgroupware Phpgroupware 0.9.12
Phpgroupware Phpgroupware 0.9.13
Phpgroupware Phpgroupware 0.9.16.002
Phpgroupware Phpgroupware 0.9.16.003
Phpgroupware Phpgroupware 0.9.14.005
Phpgroupware Phpgroupware 0.9.14.006
2 EDB exploits
755
VMScore
CVE-2004-1383
Multiple SQL injection vulnerabilities in phpGroupWare 0.9.16.003 and previous versions allow remote malicious users to execute arbitrary SQL statements via the (1) order, (2) project_id, (3) pro_main, or (4) hours_id parameters to index.php or (5) ticket_id to viewticket_details...
Phpgroupware Phpgroupware 0.9.14.007
Phpgroupware Phpgroupware 0.9.16.000
Phpgroupware Phpgroupware 0.9.14
Phpgroupware Phpgroupware 0.9.14.003
Phpgroupware Phpgroupware 0.9.16 Rc1
Phpgroupware Phpgroupware 0.9.14.005
Phpgroupware Phpgroupware 0.9.14.006
Phpgroupware Phpgroupware 0.9.12
Phpgroupware Phpgroupware 0.9.13
Phpgroupware Phpgroupware 0.9.16.002
Phpgroupware Phpgroupware 0.9.16.003
1 EDB exploit
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-4367
CVE-2024-35977
CVE-2023-49335
man-in-the-middle
CVE-2024-4947
CVE-2024-31714
memory leak
SQL
CVE-2024-35994
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »