5
CVSSv2

CVE-2004-2578

Published: 31/12/2004 Updated: 11/07/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

phpGroupWare prior to 0.9.16.002 transmits the (1) header admin and (2) setup passwords in plaintext via cookies, which allows remote malicious users to sniff passwords.

Vulnerable Product Search on Vulmon Subscribe to Product

phpgroupware phpgroupware 0.9.1

phpgroupware phpgroupware 0.9.16.000

phpgroupware phpgroupware 0.9.16.001

phpgroupware phpgroupware 0.9.8

phpgroupware phpgroupware 0.9.9

phpgroupware phpgroupware 0.9.14.005

phpgroupware phpgroupware 0.9.14.006

phpgroupware phpgroupware 0.9.14.007

phpgroupware phpgroupware 0.9.6

phpgroupware phpgroupware 0.9.7

phpgroupware phpgroupware 0.9.13

phpgroupware phpgroupware 0.9.14.003

phpgroupware phpgroupware 0.9.4

phpgroupware phpgroupware 0.9.5

phpgroupware phpgroupware 0.9.10

phpgroupware phpgroupware 0.9.12

phpgroupware phpgroupware 0.9.2

phpgroupware phpgroupware 0.9.3

phpgroupware phpgroupware 0.9.9_pl1