7.5
CVSSv2

CVE-2010-0404

Published: 19/05/2010 Updated: 10/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in phpGroupWare (phpgw) prior to 0.9.16.016 allow remote malicious users to execute arbitrary SQL commands via unspecified parameters to (1) class.sessions_db.inc.php, (2) class.translation_sql.inc.php, or (3) class.auth_sql.inc.php in phpgwapi/inc/.

Vulnerable Product Search on Vulmon Subscribe to Product

phpgroupware phpgroupware 0.9.16.014

phpgroupware phpgroupware 0.9.16.012

phpgroupware phpgroupware 0.9.16.011

phpgroupware phpgroupware 0.9.16

phpgroupware phpgroupware

phpgroupware phpgroupware 0.9.16.001

phpgroupware phpgroupware 0.9.16.000

phpgroupware phpgroupware 0.9.16.010

phpgroupware phpgroupware 0.9.16.005

phpgroupware phpgroupware 0.9.16.003

phpgroupware phpgroupware 0.9.16.002

Vendor Advisories

Several remote vulnerabilities have been discovered in phpgroupware, a Web based groupware system written in PHP The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2010-0403 A local file inclusion vulnerability allows remote attackers to execute arbitrary PHP code and include arbitrary local files CVE-2010-04 ...