4.3
CVSSv2

CVE-2004-1467

Published: 31/12/2004 Updated: 11/07/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in eGroupWare 1.0.00.003 and previous versions allow remote malicious users to inject arbitrary web script or HTML via (1) date or search text field in the calendar module, (2) Field parameter, Filter parameter, QField parameter, Start parameter or Search field in the address module, (3) Subject field in the message module or (4) Subject field in the Ticket module.

Vulnerable Product Search on Vulmon Subscribe to Product

egroupware egroupware 1.0

egroupware egroupware 1.0.1

egroupware egroupware 1.0.3

Exploits

source: wwwsecurityfocuscom/bid/11013/info It is reported that eGroupWare is susceptible to multiple cross-site scripting and HTML injection vulnerabilities The cross-site scripting issues present themselves in the various parameters of the 'addressbook' and 'calendar' modules It is also reported that data input through the 'Search' fi ...