4.3
CVSSv2

CVE-2004-1384

Published: 31/12/2004 Updated: 11/07/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 440
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in phpGroupWare 0.9.16.003 and previous versions allow remote malicious users to inject arbitrary web script or HTML via the (1) kp3, (2) type, (3) msg, (4) forum_id, (5) pos, (6) cats_app, (7) cat_id, (8) msgball[msgnum], (9) fldball[acctnum] parameters to index.php or (10) ticket_id to viewticket_details.php.

Vulnerable Product Search on Vulmon Subscribe to Product

phpgroupware phpgroupware 0.9.14

phpgroupware phpgroupware 0.9.14.003

phpgroupware phpgroupware 0.9.16_rc1

phpgroupware phpgroupware 0.9.14.007

phpgroupware phpgroupware 0.9.16.000

phpgroupware phpgroupware 0.9.12

phpgroupware phpgroupware 0.9.13

phpgroupware phpgroupware 0.9.16.002

phpgroupware phpgroupware 0.9.16.003

phpgroupware phpgroupware 0.9.14.005

phpgroupware phpgroupware 0.9.14.006

Exploits

source: wwwsecurityfocuscom/bid/11952/info Reportedly PHPGroupWare contains multiple input validation vulnerabilities; it is prone to multiple SQL injection and cross-site scripting issues These issues are all due to a failure of the application to properly sanitize user-supplied input The SQL injection issues may allow a remote attac ...
source: wwwsecurityfocuscom/bid/11952/info Reportedly PHPGroupWare contains multiple input validation vulnerabilities; it is prone to multiple SQL injection and cross-site scripting issues These issues are all due to a failure of the application to properly sanitize user-supplied input The SQL injection issues may allow a remote atta ...