Filtered by vendor Phpgroupware
Subscriptions
Filtered by product Phpgroupware
Subscriptions
Total
27 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2005-2761 | 1 Phpgroupware | 1 Phpgroupware | 2024-08-07 | N/A |
Cross-site scripting (XSS) vulnerability in phpGroupWare 0.9.16.000 allows administrators to inject arbitrary web script or HTML by modifying the main screen message. | ||||
CVE-2006-4458 | 1 Phpgroupware | 1 Phpgroupware | 2024-08-07 | N/A |
Directory traversal vulnerability in calendar/inc/class.holidaycalc.inc.php in phpGroupWare 0.9.16.010 and earlier allows remote attackers to include arbitrary local files via a .. (dot dot) sequence and trailing null (%00) byte in the GLOBALS[phpgw_info][user][preferences][common][country] parameter. | ||||
CVE-2009-4414 | 1 Phpgroupware | 1 Phpgroupware | 2024-08-07 | N/A |
SQL injection vulnerability in phpgwapi /inc/class.auth_sql.inc.php in phpGroupWare 0.9.16.12, and possibly other versions before 0.9.16.014, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the passwd parameter to login.php. | ||||
CVE-2009-4415 | 1 Phpgroupware | 1 Phpgroupware | 2024-08-07 | N/A |
Multiple directory traversal vulnerabilities in phpGroupWare 0.9.16.12, and possibly other versions before 0.9.16.014, allow remote attackers to (1) read arbitrary files via the csvfile parameter to addressbook/csv_import.php, or (2) include and execute arbitrary local files via the conv_type parameter in addressbook/inc/class.uiXport.inc.php. | ||||
CVE-2009-4416 | 1 Phpgroupware | 1 Phpgroupware | 2024-08-07 | N/A |
Cross-site scripting (XSS) vulnerability in login.php in phpGroupWare 0.9.16.12, and possibly other versions before 0.9.16.014, allows remote attackers to inject arbitrary web script or HTML via an arbitrary parameter whose name begins with the "phpgw_" sequence. | ||||
CVE-2010-0404 | 1 Phpgroupware | 1 Phpgroupware | 2024-08-07 | N/A |
Multiple SQL injection vulnerabilities in phpGroupWare (phpgw) before 0.9.16.016 allow remote attackers to execute arbitrary SQL commands via unspecified parameters to (1) class.sessions_db.inc.php, (2) class.translation_sql.inc.php, or (3) class.auth_sql.inc.php in phpgwapi/inc/. | ||||
CVE-2010-0403 | 1 Phpgroupware | 1 Phpgroupware | 2024-08-07 | N/A |
Directory traversal vulnerability in about.php in phpGroupWare (phpgw) before 0.9.16.016 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the app parameter. |