7.5
CVSSv2

CVE-2004-2573

Published: 31/12/2004 Updated: 05/09/2008
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

PHP remote file inclusion vulnerability in tables_update.inc.php in phpGroupWare 0.9.14.005 and previous versions allows remote malicious users to execute arbitrary PHP code via an external URL in the appdir parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

phpgroupware phpgroupware 0.9.14.003

phpgroupware phpgroupware

Exploits

source: wwwsecurityfocuscom/bid/12074/info phpGroupWare is prone to a remote file include vulnerability, potentially allowing the execution of malicious PHP code This would occur in the context of the affected web server The tables_updateincphp script contains the following include calls: /* Include older phpGroupWare update support ...