6.8
CVSSv2

CVE-2010-0403

Published: 19/05/2010 Updated: 10/10/2018
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Directory traversal vulnerability in about.php in phpGroupWare (phpgw) prior to 0.9.16.016 allows remote malicious users to include and execute arbitrary local files via a .. (dot dot) in the app parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

phpgroupware phpgroupware 0.9.16.014

phpgroupware phpgroupware 0.9.16.012

phpgroupware phpgroupware 0.9.16.005

phpgroupware phpgroupware 0.9.16.003

phpgroupware phpgroupware 0.9.16.011

phpgroupware phpgroupware 0.9.16.010

phpgroupware phpgroupware

phpgroupware phpgroupware 0.9.16.002

phpgroupware phpgroupware 0.9.16.001

phpgroupware phpgroupware 0.9.16.000

phpgroupware phpgroupware 0.9.16

Vendor Advisories

Several remote vulnerabilities have been discovered in phpgroupware, a Web based groupware system written in PHP The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2010-0403 A local file inclusion vulnerability allows remote attackers to execute arbitrary PHP code and include arbitrary local files CVE-2010-04 ...