7.5
CVSSv2

CVE-2004-1383

Published: 31/12/2004 Updated: 11/07/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in phpGroupWare 0.9.16.003 and previous versions allow remote malicious users to execute arbitrary SQL statements via the (1) order, (2) project_id, (3) pro_main, or (4) hours_id parameters to index.php or (5) ticket_id to viewticket_details.php.

Vulnerable Product Search on Vulmon Subscribe to Product

phpgroupware phpgroupware 0.9.14.003

phpgroupware phpgroupware 0.9.13

phpgroupware phpgroupware 0.9.14.005

phpgroupware phpgroupware 0.9.14.006

phpgroupware phpgroupware 0.9.12

phpgroupware phpgroupware 0.9.14

phpgroupware phpgroupware 0.9.16.000

phpgroupware phpgroupware 0.9.16.003

phpgroupware phpgroupware 0.9.16 rc1

phpgroupware phpgroupware 0.9.16.002

phpgroupware phpgroupware 0.9.14.007

Exploits

source: wwwsecurityfocuscom/bid/11952/info Reportedly PHPGroupWare contains multiple input validation vulnerabilities; it is prone to multiple SQL injection and cross-site scripting issues These issues are all due to a failure of the application to properly sanitize user-supplied input The SQL injection issues may allow a remote atta ...