5
CVSSv2

CVE-2004-1385

Published: 31/12/2004 Updated: 11/07/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

phpGroupWare 0.9.16.003 and previous versions allows remote malicious users to gain sensitive information via (1) unexpected characters in the session ID such as shell metacharacters, (2) an invalid appname parameter to preferences.php or (3) an invalid menuaction parameter to index.php, which reveals the web server path in an error message.

Vulnerable Product Search on Vulmon Subscribe to Product

phpgroupware phpgroupware 0.9.16.000

phpgroupware phpgroupware 0.9.16.002

phpgroupware phpgroupware 0.9.14.003

phpgroupware phpgroupware 0.9.14.005

phpgroupware phpgroupware 0.9.14.006

phpgroupware phpgroupware 0.9.14.007

phpgroupware phpgroupware 0.9.12

phpgroupware phpgroupware 0.9.13

phpgroupware phpgroupware 0.9.14

phpgroupware phpgroupware 0.9.16.003

phpgroupware phpgroupware 0.9.16_rc1

Exploits

source: wwwsecurityfocuscom/bid/11952/info Reportedly PHPGroupWare contains multiple input validation vulnerabilities; it is prone to multiple SQL injection and cross-site scripting issues These issues are all due to a failure of the application to properly sanitize user-supplied input The SQL injection issues may allow a remote atta ...