4.3
CVSSv2

CVE-2010-3314

Published: 22/09/2010 Updated: 22/09/2010
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in login.php in EGroupware 1.4.001+.002; 1.6.001+.002 and possibly other versions prior to 1.6.003; and EPL 9.1 prior to 9.1.20100309 and 9.2 prior to 9.2.20100309; allows remote malicious users to inject arbitrary web script or HTML via the lang parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

egroupware egroupware 1.4.001

egroupware egroupware 1.6.001\\+.002

egroupware egroupware 9.1

egroupware egroupware 9.2

egroupware egroupware 1.4.001\\+.002

egroupware egroupware 1.6.002

egroupware egroupware 1.4.002

egroupware egroupware 1.6.001

Exploits

Advisory Name: Remote Command Execution in EGroupware Vulnerability Class: Remote Command Execution Release Date: 2010-03-09 Affected Applications: Confirmed in EGroupware 14001+002 and 16001+002 EGroupware Premium Line 91 and 92 is also affected Other versions may also be affected Affected Platforms: Multiple Local / Remote: Remot ...