7.5
CVSSv2

CVE-2004-0016

Published: 03/02/2004 Updated: 10/10/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The calendar module for phpgroupware 0.9.14 does not enforce the "save extension" feature for holiday files, which allows remote malicious users to create and execute PHP files.

Vulnerable Product Search on Vulmon Subscribe to Product

phpgroupware phpgroupware 0.9.14

Vendor Advisories

The authors of phpgroupware, a web based groupware system written in PHP, discovered several vulnerabilities The Common Vulnerabilities and Exposures project identifies the following problems: CAN-2004-0016 In the "calendar" module, "save extension" was not enforced for holiday files As a result, server-side php scripts may be placed in dire ...