Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
phpgroupware phpgroupware vulnerabilities and exploits
(subscribe to this query)
7.5
CVSSv2
CVE-2009-4415
Multiple directory traversal vulnerabilities in phpGroupWare 0.9.16.12, and possibly other versions prior to 0.9.16.014, allow remote malicious users to (1) read arbitrary files via the csvfile parameter to addressbook/csv_import.php, or (2) include and execute arbitrary local fi...
Phpgroupware Phpgroupware 0.9.16.12
4.3
CVSSv2
CVE-2009-4416
Cross-site scripting (XSS) vulnerability in login.php in phpGroupWare 0.9.16.12, and possibly other versions prior to 0.9.16.014, allows remote malicious users to inject arbitrary web script or HTML via an arbitrary parameter whose name begins with the "phpgw_" sequence...
Phpgroupware Phpgroupware 0.9.16.12
7.5
CVSSv2
CVE-2002-0536
PHPGroupware 0.9.12 and previous versions, when running with the magic_quotes_gpc feature disabled, allows remote malicious users to compromise the database via a SQL injection attack.
Phpgroupware Phpgroupware 0.9.13
1 EDB exploit
5
CVSSv2
CVE-2004-2576
class.vfs_dav.inc.php in phpGroupWare 0.9.16.000 does not create .htaccess files to enable authorization checks for access to users' home-directory files, which allows remote malicious users to obtain sensitive information from these files.
Phpgroupware Phpgroupware 0.9.16.000
6.4
CVSSv2
CVE-2006-4458
Directory traversal vulnerability in calendar/inc/class.holidaycalc.inc.php in phpGroupWare 0.9.16.010 and previous versions allows remote malicious users to include arbitrary local files via a .. (dot dot) sequence and trailing null (%00) byte in the GLOBALS[phpgw_info][user][pr...
Phpgroupware Phpgroupware 0.9.16.010
1 EDB exploit
6.8
CVSSv2
CVE-2009-4414
SQL injection vulnerability in phpgwapi /inc/class.auth_sql.inc.php in phpGroupWare 0.9.16.12, and possibly other versions prior to 0.9.16.014, when magic_quotes_gpc is disabled, allows remote malicious users to execute arbitrary SQL commands via the passwd parameter to login.php...
Phpgroupware Phpgroupware 0.9.16.012
4.3
CVSSv2
CVE-2005-2761
Cross-site scripting (XSS) vulnerability in phpGroupWare 0.9.16.000 allows administrators to inject arbitrary web script or HTML by modifying the main screen message.
Phpgroupware Phpgroupware 0.9.16.000
7.5
CVSSv2
CVE-2005-2781
The Avatar upload feature in FUD Forum prior to 2.7.0 does not properly verify uploaded files, which allows remote malicious users to execute arbitrary PHP code via a file with a .php extension that contains image data followed by PHP code.
Ilia Alshanetsky Fudforum 2.2.0
Ilia Alshanetsky Fudforum 2.2.1
Ilia Alshanetsky Fudforum 2.2.2
Ilia Alshanetsky Fudforum 2.3.3
Ilia Alshanetsky Fudforum 2.3.4
Ilia Alshanetsky Fudforum 2.5.2
Ilia Alshanetsky Fudforum 2.6.0
Ilia Alshanetsky Fudforum 2.6.2
Ilia Alshanetsky Fudforum 2.6.3
Ilia Alshanetsky Fudforum 2.7.0
Ilia Alshanetsky Fudforum 2.2.3
Ilia Alshanetsky Fudforum 2.2.4
Ilia Alshanetsky Fudforum 2.3.5
Ilia Alshanetsky Fudforum 2.3.6
Ilia Alshanetsky Fudforum 2.6.1
Ilia Alshanetsky Fudforum 2.6.10
Ilia Alshanetsky Fudforum 2.6.4
Ilia Alshanetsky Fudforum 2.6.5
Ilia Alshanetsky Fudforum 2.1.0
Ilia Alshanetsky Fudforum 2.1.1
Ilia Alshanetsky Fudforum 2.2.5
Ilia Alshanetsky Fudforum 2.3.0
5
CVSSv2
CVE-2005-2600
FUDForum 2.6.15 with "Tree View" enabled, as used in other products such as phpgroupware and egroupware, allows remote malicious users to read private posts via a modified mid parameter.
Ilia Alshanetsky Fudforum 2.6.15
7.5
CVSSv2
CVE-2005-2498
Eval injection vulnerability in PHPXMLRPC 1.1.1 and previous versions (PEAR XML-RPC for PHP), as used in multiple products including (1) Drupal, (2) phpAdsNew, (3) phpPgAds, and (4) phpgroupware, allows remote malicious users to execute arbitrary PHP code via certain nested XML t...
Gggeek Phpxmlrpc
Debian Debian Linux 3.1
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
firewall
CVE-2024-35649
stored XSS
CVE-2022-28654
CVE-2020-35153
CVE-2024-27348
CVE-2022-28652
local users
CVE-2017-3506
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
NEXT »