7.5
CVSSv2

CVE-2003-0657

Published: 27/08/2003 Updated: 05/09/2008
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in the infolog module for phpgroupware 0.9.14 and previous versions could allow remote malicious users to conduct unauthorized database actions.

Vulnerable Product Search on Vulmon Subscribe to Product

phpgroupware phpgroupware

Vendor Advisories

Several vulnerabilities have been discovered in phpgroupware: CAN-2003-0504: Multiple cross-site scripting (XSS) vulnerabilities in Phpgroupware 0914003 (aka webdistro) allow remote attackers to insert arbitrary HTML or web script, as demonstrated with a request to indexphp in the addressbook module CAN-2003-0599: Unknown vulnerability ...