Description
SQL injection vulnerability in phpgwapi /inc/class.auth_sql.inc.php in phpGroupWare 0.9.16.12, and possibly other versions before 0.9.16.014, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the passwd parameter to login.php.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-1978-1 | New phpgroupware packages fix several vulnerabilities |
EUVD |
EUVD-2009-4381 | SQL injection vulnerability in phpgwapi /inc/class.auth_sql.inc.php in phpGroupWare 0.9.16.12, and possibly other versions before 0.9.16.014, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the passwd parameter to login.php. |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-07T07:01:20.493Z
Reserved: 2009-12-24T00:00:00.000Z
Link: CVE-2009-4414
No data.
Status : Modified
Published: 2009-12-24T16:30:00.420
Modified: 2026-04-23T00:35:47.467
Link: CVE-2009-4414
No data.
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA
EUVD