Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
phpgroupware phpgroupware 0.9.16.002 vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2004-2574
Cross-site scripting (XSS) vulnerability in index.php in phpGroupWare 0.9.14.005 and previous versions allows remote malicious users to inject arbitrary web script or HTML via the date parameter in a calendar.uicalendar.planner menuaction.
Phpgroupware Phpgroupware 0.9.16.000
Phpgroupware Phpgroupware 0.9.16.002
Phpgroupware Phpgroupware 0.9.16.003
Phpgroupware Phpgroupware
1 EDB exploit
NA
CVE-2004-2575
phpGroupWare 0.9.14.005 and previous versions allow remote malicious users to obtain sensitive information via a direct request to (1) hook_admin.inc.php, (2) hook_home.inc.php, (3) class.holidaycalc.inc.php, and (4) setup.inc.php.sample, which reveals the path in an error messag...
Phpgroupware Phpgroupware 0.9.16.002
Phpgroupware Phpgroupware 0.9.16.005
Phpgroupware Phpgroupware 0.9.16.000
Phpgroupware Phpgroupware 0.9.16.003
NA
CVE-2004-0875
Multiple cross-site scripting (XSS) vulnerabilities in Phpgroupware (aka webdistro) 0.9.16.002 and previous versions allow remote malicious users to insert arbitrary HTML or web script, as demonstrated with a request to the wiki module.
Phpgroupware Phpgroupware 0.9.14.005
Phpgroupware Phpgroupware 0.9.14.006
Phpgroupware Phpgroupware 0.9.12
Phpgroupware Phpgroupware 0.9.13
Phpgroupware Phpgroupware 0.9.14.003
Phpgroupware Phpgroupware 0.9.14.007
Phpgroupware Phpgroupware 0.9.16.000
Phpgroupware Phpgroupware 0.9.16.002
Phpgroupware Phpgroupware 0.9.16 Rc1
NA
CVE-2010-0403
Directory traversal vulnerability in about.php in phpGroupWare (phpgw) prior to 0.9.16.016 allows remote malicious users to include and execute arbitrary local files via a .. (dot dot) in the app parameter.
Phpgroupware Phpgroupware 0.9.16.014
Phpgroupware Phpgroupware 0.9.16.012
Phpgroupware Phpgroupware 0.9.16.005
Phpgroupware Phpgroupware 0.9.16.003
Phpgroupware Phpgroupware 0.9.16.011
Phpgroupware Phpgroupware 0.9.16.010
Phpgroupware Phpgroupware
Phpgroupware Phpgroupware 0.9.16.002
Phpgroupware Phpgroupware 0.9.16.001
Phpgroupware Phpgroupware 0.9.16.000
Phpgroupware Phpgroupware 0.9.16
NA
CVE-2010-0404
Multiple SQL injection vulnerabilities in phpGroupWare (phpgw) prior to 0.9.16.016 allow remote malicious users to execute arbitrary SQL commands via unspecified parameters to (1) class.sessions_db.inc.php, (2) class.translation_sql.inc.php, or (3) class.auth_sql.inc.php in phpgw...
Phpgroupware Phpgroupware 0.9.16.014
Phpgroupware Phpgroupware 0.9.16.012
Phpgroupware Phpgroupware 0.9.16.011
Phpgroupware Phpgroupware 0.9.16
Phpgroupware Phpgroupware
Phpgroupware Phpgroupware 0.9.16.001
Phpgroupware Phpgroupware 0.9.16.000
Phpgroupware Phpgroupware 0.9.16.010
Phpgroupware Phpgroupware 0.9.16.005
Phpgroupware Phpgroupware 0.9.16.003
Phpgroupware Phpgroupware 0.9.16.002
NA
CVE-2004-1383
Multiple SQL injection vulnerabilities in phpGroupWare 0.9.16.003 and previous versions allow remote malicious users to execute arbitrary SQL statements via the (1) order, (2) project_id, (3) pro_main, or (4) hours_id parameters to index.php or (5) ticket_id to viewticket_details...
Phpgroupware Phpgroupware 0.9.14.007
Phpgroupware Phpgroupware 0.9.16.000
Phpgroupware Phpgroupware 0.9.14
Phpgroupware Phpgroupware 0.9.14.003
Phpgroupware Phpgroupware 0.9.16 Rc1
Phpgroupware Phpgroupware 0.9.14.005
Phpgroupware Phpgroupware 0.9.14.006
Phpgroupware Phpgroupware 0.9.12
Phpgroupware Phpgroupware 0.9.13
Phpgroupware Phpgroupware 0.9.16.002
Phpgroupware Phpgroupware 0.9.16.003
1 EDB exploit
NA
CVE-2004-1385
phpGroupWare 0.9.16.003 and previous versions allows remote malicious users to gain sensitive information via (1) unexpected characters in the session ID such as shell metacharacters, (2) an invalid appname parameter to preferences.php or (3) an invalid menuaction parameter to in...
Phpgroupware Phpgroupware 0.9.16.000
Phpgroupware Phpgroupware 0.9.16.002
Phpgroupware Phpgroupware 0.9.14.003
Phpgroupware Phpgroupware 0.9.14.005
Phpgroupware Phpgroupware 0.9.14.006
Phpgroupware Phpgroupware 0.9.14.007
Phpgroupware Phpgroupware 0.9.12
Phpgroupware Phpgroupware 0.9.13
Phpgroupware Phpgroupware 0.9.14
Phpgroupware Phpgroupware 0.9.16.003
Phpgroupware Phpgroupware 0.9.16 Rc1
1 EDB exploit
NA
CVE-2004-1384
Multiple cross-site scripting (XSS) vulnerabilities in phpGroupWare 0.9.16.003 and previous versions allow remote malicious users to inject arbitrary web script or HTML via the (1) kp3, (2) type, (3) msg, (4) forum_id, (5) pos, (6) cats_app, (7) cat_id, (8) msgball[msgnum], (9) f...
Phpgroupware Phpgroupware 0.9.14
Phpgroupware Phpgroupware 0.9.14.003
Phpgroupware Phpgroupware 0.9.16 Rc1
Phpgroupware Phpgroupware 0.9.14.007
Phpgroupware Phpgroupware 0.9.16.000
Phpgroupware Phpgroupware 0.9.12
Phpgroupware Phpgroupware 0.9.13
Phpgroupware Phpgroupware 0.9.16.002
Phpgroupware Phpgroupware 0.9.16.003
Phpgroupware Phpgroupware 0.9.14.005
Phpgroupware Phpgroupware 0.9.14.006
2 EDB exploits
NA
CVE-2004-2578
phpGroupWare prior to 0.9.16.002 transmits the (1) header admin and (2) setup passwords in plaintext via cookies, which allows remote malicious users to sniff passwords.
Phpgroupware Phpgroupware 0.9.1
Phpgroupware Phpgroupware 0.9.16.000
Phpgroupware Phpgroupware 0.9.16.001
Phpgroupware Phpgroupware 0.9.8
Phpgroupware Phpgroupware 0.9.9
Phpgroupware Phpgroupware 0.9.14.005
Phpgroupware Phpgroupware 0.9.14.006
Phpgroupware Phpgroupware 0.9.14.007
Phpgroupware Phpgroupware 0.9.6
Phpgroupware Phpgroupware 0.9.7
Phpgroupware Phpgroupware 0.9.13
Phpgroupware Phpgroupware 0.9.14.003
Phpgroupware Phpgroupware 0.9.4
Phpgroupware Phpgroupware 0.9.5
Phpgroupware Phpgroupware 0.9.10
Phpgroupware Phpgroupware 0.9.12
Phpgroupware Phpgroupware 0.9.2
Phpgroupware Phpgroupware 0.9.3
Phpgroupware Phpgroupware 0.9.9 Pl1
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-4644
unprivileged
CVE-2024-3494
CVE-2024-22460
CVE-2024-26026
CVE-2024-23473
firewall
CVE-2024-28889
XML external entity
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started