4.3
CVSSv2

CVE-2005-2761

Published: 31/08/2005 Updated: 05/09/2008
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in phpGroupWare 0.9.16.000 allows administrators to inject arbitrary web script or HTML by modifying the main screen message.

Vulnerable Product Search on Vulmon Subscribe to Product

phpgroupware phpgroupware 0.9.16.000

Vendor Advisories

Several vulnerabilities have been discovered in phpgroupware, a web based groupware system written in PHP The Common Vulnerabilities and Exposures project identifies the following problems: CAN-2005-2498 Stefan Esser discovered another vulnerability in the XML-RPC libraries that allows injection of arbitrary PHP code into eval() state ...