Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
phpgroupware phpgroupware 0.9.13 vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2002-0536
PHPGroupware 0.9.12 and previous versions, when running with the magic_quotes_gpc feature disabled, allows remote malicious users to compromise the database via a SQL injection attack.
Phpgroupware Phpgroupware 0.9.13
1 EDB exploit
NA
CVE-2004-0875
Multiple cross-site scripting (XSS) vulnerabilities in Phpgroupware (aka webdistro) 0.9.16.002 and previous versions allow remote malicious users to insert arbitrary HTML or web script, as demonstrated with a request to the wiki module.
Phpgroupware Phpgroupware 0.9.14.005
Phpgroupware Phpgroupware 0.9.14.006
Phpgroupware Phpgroupware 0.9.12
Phpgroupware Phpgroupware 0.9.13
Phpgroupware Phpgroupware 0.9.14.003
Phpgroupware Phpgroupware 0.9.14.007
Phpgroupware Phpgroupware 0.9.16.000
Phpgroupware Phpgroupware 0.9.16.002
Phpgroupware Phpgroupware 0.9.16 Rc1
NA
CVE-2004-1383
Multiple SQL injection vulnerabilities in phpGroupWare 0.9.16.003 and previous versions allow remote malicious users to execute arbitrary SQL statements via the (1) order, (2) project_id, (3) pro_main, or (4) hours_id parameters to index.php or (5) ticket_id to viewticket_details...
Phpgroupware Phpgroupware 0.9.14.007
Phpgroupware Phpgroupware 0.9.16.000
Phpgroupware Phpgroupware 0.9.14
Phpgroupware Phpgroupware 0.9.14.003
Phpgroupware Phpgroupware 0.9.16 Rc1
Phpgroupware Phpgroupware 0.9.14.005
Phpgroupware Phpgroupware 0.9.14.006
Phpgroupware Phpgroupware 0.9.12
Phpgroupware Phpgroupware 0.9.13
Phpgroupware Phpgroupware 0.9.16.002
Phpgroupware Phpgroupware 0.9.16.003
1 EDB exploit
NA
CVE-2004-1384
Multiple cross-site scripting (XSS) vulnerabilities in phpGroupWare 0.9.16.003 and previous versions allow remote malicious users to inject arbitrary web script or HTML via the (1) kp3, (2) type, (3) msg, (4) forum_id, (5) pos, (6) cats_app, (7) cat_id, (8) msgball[msgnum], (9) f...
Phpgroupware Phpgroupware 0.9.14
Phpgroupware Phpgroupware 0.9.14.003
Phpgroupware Phpgroupware 0.9.16 Rc1
Phpgroupware Phpgroupware 0.9.14.007
Phpgroupware Phpgroupware 0.9.16.000
Phpgroupware Phpgroupware 0.9.12
Phpgroupware Phpgroupware 0.9.13
Phpgroupware Phpgroupware 0.9.16.002
Phpgroupware Phpgroupware 0.9.16.003
Phpgroupware Phpgroupware 0.9.14.005
Phpgroupware Phpgroupware 0.9.14.006
2 EDB exploits
NA
CVE-2004-1385
phpGroupWare 0.9.16.003 and previous versions allows remote malicious users to gain sensitive information via (1) unexpected characters in the session ID such as shell metacharacters, (2) an invalid appname parameter to preferences.php or (3) an invalid menuaction parameter to in...
Phpgroupware Phpgroupware 0.9.16.000
Phpgroupware Phpgroupware 0.9.16.002
Phpgroupware Phpgroupware 0.9.14.003
Phpgroupware Phpgroupware 0.9.14.005
Phpgroupware Phpgroupware 0.9.14.006
Phpgroupware Phpgroupware 0.9.14.007
Phpgroupware Phpgroupware 0.9.12
Phpgroupware Phpgroupware 0.9.13
Phpgroupware Phpgroupware 0.9.14
Phpgroupware Phpgroupware 0.9.16.003
Phpgroupware Phpgroupware 0.9.16 Rc1
1 EDB exploit
NA
CVE-2004-2578
phpGroupWare prior to 0.9.16.002 transmits the (1) header admin and (2) setup passwords in plaintext via cookies, which allows remote malicious users to sniff passwords.
Phpgroupware Phpgroupware 0.9.1
Phpgroupware Phpgroupware 0.9.16.000
Phpgroupware Phpgroupware 0.9.16.001
Phpgroupware Phpgroupware 0.9.8
Phpgroupware Phpgroupware 0.9.9
Phpgroupware Phpgroupware 0.9.14.005
Phpgroupware Phpgroupware 0.9.14.006
Phpgroupware Phpgroupware 0.9.14.007
Phpgroupware Phpgroupware 0.9.6
Phpgroupware Phpgroupware 0.9.7
Phpgroupware Phpgroupware 0.9.13
Phpgroupware Phpgroupware 0.9.14.003
Phpgroupware Phpgroupware 0.9.4
Phpgroupware Phpgroupware 0.9.5
Phpgroupware Phpgroupware 0.9.10
Phpgroupware Phpgroupware 0.9.12
Phpgroupware Phpgroupware 0.9.2
Phpgroupware Phpgroupware 0.9.3
Phpgroupware Phpgroupware 0.9.9 Pl1
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-35229
privilege escalation
local users
CVE-2024-5405
CVE-2024-27842
CVE-2024-5274
CVE-2024-5378
CVE-2024-34152
hard-coded
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started