7.5
CVSSv2

CVE-2004-0017

Published: 03/02/2004 Updated: 05/09/2008
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in the (1) calendar and (2) infolog modules for phpgroupware 0.9.14 allow remote malicious users to perform unauthorized database operations.

Vulnerable Product Search on Vulmon Subscribe to Product

phpgroupware phpgroupware 0.9.14

Vendor Advisories

The authors of phpgroupware, a web based groupware system written in PHP, discovered several vulnerabilities The Common Vulnerabilities and Exposures project identifies the following problems: CAN-2004-0016 In the "calendar" module, "save extension" was not enforced for holiday files As a result, server-side php scripts may be placed in dire ...