10
CVSSv2

CVE-2003-0599

Published: 27/08/2003 Updated: 05/09/2008
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Unknown vulnerability in the Virtual File System (VFS) capability for phpGroupWare 0.9.16preRC and versions prior to 0.9.14.004 with unknown implications, related to the VFS path being under the web document root.

Vulnerable Product Search on Vulmon Subscribe to Product

phpgroupware phpgroupware

phpgroupware phpgroupware 0.9.16prerc

Vendor Advisories

Several vulnerabilities have been discovered in phpgroupware: CAN-2003-0504: Multiple cross-site scripting (XSS) vulnerabilities in Phpgroupware 0914003 (aka webdistro) allow remote attackers to insert arbitrary HTML or web script, as demonstrated with a request to indexphp in the addressbook module CAN-2003-0599: Unknown vulnerability ...