Записи phpgroupware
27 опубликованных записей вендора phpgroupware.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 7
- С записью об исправлении
- 44,4 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Записи по годам
Столбик: всего · тёмная часть: CISA KEV.
Повторяющиеся классы
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
27 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
41В плане | CVE-2001-0043Эксплойта нет | phpGroupWare before 0.9.7 allows remote attackers to execute arbitrary PHP commands by specifying a malicious include file in the phpgw_infophpgroupware · phpgroupware | Критическая10,0 | — | 3,1 % | 16 февр. 2001 г. |
41В плане | CVE-2003-0599Эксплойта нет | Unknown vulnerability in the Virtual File System (VFS) capability for phpGroupWare 0.9.16preRC and versions before 0.9.14.004 with unknown iphpgroupware · phpgroupware | Критическая10,0 | — | 1,8 % | 27 авг. 2003 г. |
40В плане | CVE-2004-2407Эксплойта нет | Unknown vulnerability in phpGroupWare before 0.9.14.002 has unknown attack vectors and impact, related to a "security hole" in the Setup/Conphpgroupware · phpgroupware | Критическая10,0 | — | 1,5 % | 31 дек. 2004 г. |
40В плане | CVE-2004-2406Эксплойта нет | Unknown "overflow" in the phpgw_config table for phpGroupWare before 0.9.14.002 has unknown attack vectors and impact.phpgroupware · phpgroupware | Критическая10,0 | — | 1,4 % | 31 дек. 2004 г. |
31Наблюдать | CVE-2009-4415Эксплойта нет | Multiple directory traversal vulnerabilities in phpGroupWare 0.9.16.12, and possibly other versions before 0.9.16.014, allow remote attackerphpgroupware · phpgroupware · CWE-22 | Высокая7,5 | — | 3,4 % | 24 дек. 2009 г. |
31Наблюдать | CVE-2004-1383Proof of concept | Multiple SQL injection vulnerabilities in phpGroupWare 0.9.16.003 and earlier allow remote attackers to execute arbitrary SQL statements viaphpgroupware · phpgroupware | Высокая7,5 | — | 2,8 % | 31 дек. 2004 г. |
31Наблюдать | CVE-2004-2573Proof of concept | PHP remote file inclusion vulnerability in tables_update.inc.php in phpGroupWare 0.9.14.005 and earlier allows remote attackers to execute aphpgroupware · phpgroupware | Высокая7,5 | — | 2,6 % | 31 дек. 2004 г. |
31Наблюдать | CVE-2002-0536Proof of concept | PHPGroupware 0.9.12 and earlier, when running with the magic_quotes_gpc feature disabled, allows remote attackers to compromise the databasephpgroupware · phpgroupware | Высокая7,5 | — | 2,5 % | 3 июл. 2002 г. |
31Наблюдать | CVE-2010-0404Эксплойта нет | Multiple SQL injection vulnerabilities in phpGroupWare (phpgw) before 0.9.16.016 allow remote attackers to execute arbitrary SQL commands viphpgroupware · phpgroupware · CWE-89 | Высокая7,5 | — | 2,3 % | 19 мая 2010 г. |
30Наблюдать | CVE-2004-0016Эксплойта нет | The calendar module for phpgroupware 0.9.14 does not enforce the "save extension" feature for holiday files, which allows remote attackers tphpgroupware · phpgroupware | Высокая7,5 | — | 1,6 % | 3 февр. 2004 г. |
30Наблюдать | CVE-2003-0657Эксплойта нет | Multiple SQL injection vulnerabilities in the infolog module for phpgroupware 0.9.14 and earlier could allow remote attackers to conduct unaphpgroupware · phpgroupware | Высокая7,5 | — | 1,3 % | 27 авг. 2003 г. |
30Наблюдать | CVE-2004-0017Эксплойта нет | Multiple SQL injection vulnerabilities in the (1) calendar and (2) infolog modules for phpgroupware 0.9.14 allow remote attackers to performphpgroupware · phpgroupware | Высокая7,5 | — | 1,2 % | 3 февр. 2004 г. |
28Наблюдать | CVE-2005-3347Эксплойта нет | Multiple directory traversal vulnerabilities in index.php in phpSysInfo 2.4 and earlier, as used in phpgroupware 0.9.16 and earlier, and egrphpgroupware · phpgroupware · CWE-22 | Средняя6,8 | — | 3,5 % | 17 нояб. 2005 г. |
28Наблюдать | CVE-2010-0403Эксплойта нет | Directory traversal vulnerability in about.php in phpGroupWare (phpgw) before 0.9.16.016 allows remote attackers to include and execute arbiphpgroupware · phpgroupware · CWE-22 | Средняя6,8 | — | 2,0 % | 19 мая 2010 г. |
27Наблюдать | CVE-2004-0875Эксплойта нет | Multiple cross-site scripting (XSS) vulnerabilities in Phpgroupware (aka webdistro) 0.9.16.002 and earlier allow remote attackers to insert phpgroupware · phpgroupware | Средняя6,8 | — | 1,3 % | 23 дек. 2004 г. |
27Наблюдать | CVE-2009-4414Эксплойта нет | SQL injection vulnerability in phpgwapi /inc/class.auth_sql.inc.php in phpGroupWare 0.9.16.12, and possibly other versions before 0.9.16.014phpgroupware · phpgroupware · CWE-89 | Средняя6,8 | — | 1,3 % | 24 дек. 2009 г. |
26Наблюдать | CVE-2006-4458Proof of concept | Directory traversal vulnerability in calendar/inc/class.holidaycalc.inc.php in phpGroupWare 0.9.16.010 and earlier allows remote attackers tphpgroupware · phpgroupware | Средняя6,4 | — | 3,3 % | 31 авг. 2006 г. |
22Наблюдать | CVE-2004-1385Proof of concept | phpGroupWare 0.9.16.003 and earlier allows remote attackers to gain sensitive information via (1) unexpected characters in the session ID suphpgroupware · phpgroupware | Средняя5,0 | — | 7,3 % | 31 дек. 2004 г. |
20Наблюдать | CVE-2004-2575Эксплойта нет | phpGroupWare 0.9.14.005 and earlier allow remote attackers to obtain sensitive information via a direct request to (1) hook_admin.inc.php, (phpgroupware · phpgroupware | Средняя5,0 | — | 1,5 % | 31 дек. 2004 г. |
20Наблюдать | CVE-2004-2576Эксплойта нет | class.vfs_dav.inc.php in phpGroupWare 0.9.16.000 does not create .htaccess files to enable authorization checks for access to users' home-diphpgroupware · phpgroupware | Средняя5,0 | — | 1,5 % | 31 дек. 2004 г. |
20Наблюдать | CVE-2004-2578Эксплойта нет | phpGroupWare before 0.9.16.002 transmits the (1) header admin and (2) setup passwords in plaintext via cookies, which allows remote attackerphpgroupware · phpgroupware | Средняя5,0 | — | 1,4 % | 31 дек. 2004 г. |
20Наблюдать | CVE-2004-2577Эксплойта нет | The acl_check function in phpGroupWare 0.9.16RC2 always returns True, even when mkdir does not behave as expected, which could allow remote phpgroupware · phpgroupware | Средняя5,0 | — | 1,4 % | 31 дек. 2004 г. |
18Наблюдать | CVE-2004-1384Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in phpGroupWare 0.9.16.003 and earlier allow remote attackers to inject arbitrary web scphpgroupware · phpgroupware | Средняя4,3 | — | 4,0 % | 31 дек. 2004 г. |
18Наблюдать | CVE-2004-2574Proof of concept | Cross-site scripting (XSS) vulnerability in index.php in phpGroupWare 0.9.14.005 and earlier allows remote attackers to inject arbitrary webphpgroupware · phpgroupware | Средняя4,3 | — | 3,6 % | 31 дек. 2004 г. |
18Наблюдать | CVE-2009-4416Эксплойта нет | Cross-site scripting (XSS) vulnerability in login.php in phpGroupWare 0.9.16.12, and possibly other versions before 0.9.16.014, allows remotphpgroupware · phpgroupware · CWE-79 | Средняя4,3 | — | 2,3 % | 24 дек. 2009 г. |
- CVE-2001-004341В плане
phpGroupWare before 0.9.7 allows remote attackers to execute arbitrary PHP commands by specifying a malicious include file in the phpgw_info
КритическаяCVSS 10,0Эксплойта нетEPSS 3 %phpgroupware · phpgroupware16 февр. 2001 г.
- CVE-2003-059941В плане
Unknown vulnerability in the Virtual File System (VFS) capability for phpGroupWare 0.9.16preRC and versions before 0.9.14.004 with unknown i
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %phpgroupware · phpgroupware27 авг. 2003 г.
- CVE-2004-240740В плане
Unknown vulnerability in phpGroupWare before 0.9.14.002 has unknown attack vectors and impact, related to a "security hole" in the Setup/Con
КритическаяCVSS 10,0Эксплойта нетEPSS 1 %phpgroupware · phpgroupware31 дек. 2004 г.
- CVE-2004-240640В плане
Unknown "overflow" in the phpgw_config table for phpGroupWare before 0.9.14.002 has unknown attack vectors and impact.
КритическаяCVSS 10,0Эксплойта нетEPSS 1 %phpgroupware · phpgroupware31 дек. 2004 г.
- CVE-2009-441531Наблюдать
Multiple directory traversal vulnerabilities in phpGroupWare 0.9.16.12, and possibly other versions before 0.9.16.014, allow remote attacker
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %phpgroupware · phpgroupware24 дек. 2009 г.
- CVE-2004-138331Наблюдать
Multiple SQL injection vulnerabilities in phpGroupWare 0.9.16.003 and earlier allow remote attackers to execute arbitrary SQL statements via
ВысокаяCVSS 7,5Proof of conceptEPSS 3 %phpgroupware · phpgroupware31 дек. 2004 г.
- CVE-2004-257331Наблюдать
PHP remote file inclusion vulnerability in tables_update.inc.php in phpGroupWare 0.9.14.005 and earlier allows remote attackers to execute a
ВысокаяCVSS 7,5Proof of conceptEPSS 3 %phpgroupware · phpgroupware31 дек. 2004 г.
- CVE-2002-053631Наблюдать
PHPGroupware 0.9.12 and earlier, when running with the magic_quotes_gpc feature disabled, allows remote attackers to compromise the database
ВысокаяCVSS 7,5Proof of conceptEPSS 3 %phpgroupware · phpgroupware3 июл. 2002 г.
- CVE-2010-040431Наблюдать
Multiple SQL injection vulnerabilities in phpGroupWare (phpgw) before 0.9.16.016 allow remote attackers to execute arbitrary SQL commands vi
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %phpgroupware · phpgroupware19 мая 2010 г.
- CVE-2004-001630Наблюдать
The calendar module for phpgroupware 0.9.14 does not enforce the "save extension" feature for holiday files, which allows remote attackers t
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %phpgroupware · phpgroupware3 февр. 2004 г.
- CVE-2003-065730Наблюдать
Multiple SQL injection vulnerabilities in the infolog module for phpgroupware 0.9.14 and earlier could allow remote attackers to conduct una
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %phpgroupware · phpgroupware27 авг. 2003 г.
- CVE-2004-001730Наблюдать
Multiple SQL injection vulnerabilities in the (1) calendar and (2) infolog modules for phpgroupware 0.9.14 allow remote attackers to perform
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %phpgroupware · phpgroupware3 февр. 2004 г.
- CVE-2005-334728Наблюдать
Multiple directory traversal vulnerabilities in index.php in phpSysInfo 2.4 and earlier, as used in phpgroupware 0.9.16 and earlier, and egr
СредняяCVSS 6,8Эксплойта нетEPSS 4 %phpgroupware · phpgroupware17 нояб. 2005 г.
- CVE-2010-040328Наблюдать
Directory traversal vulnerability in about.php in phpGroupWare (phpgw) before 0.9.16.016 allows remote attackers to include and execute arbi
СредняяCVSS 6,8Эксплойта нетEPSS 2 %phpgroupware · phpgroupware19 мая 2010 г.
- CVE-2004-087527Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in Phpgroupware (aka webdistro) 0.9.16.002 and earlier allow remote attackers to insert
СредняяCVSS 6,8Эксплойта нетEPSS 1 %phpgroupware · phpgroupware23 дек. 2004 г.
- CVE-2009-441427Наблюдать
SQL injection vulnerability in phpgwapi /inc/class.auth_sql.inc.php in phpGroupWare 0.9.16.12, and possibly other versions before 0.9.16.014
СредняяCVSS 6,8Эксплойта нетEPSS 1 %phpgroupware · phpgroupware24 дек. 2009 г.
- CVE-2006-445826Наблюдать
Directory traversal vulnerability in calendar/inc/class.holidaycalc.inc.php in phpGroupWare 0.9.16.010 and earlier allows remote attackers t
СредняяCVSS 6,4Proof of conceptEPSS 3 %phpgroupware · phpgroupware31 авг. 2006 г.
- CVE-2004-138522Наблюдать
phpGroupWare 0.9.16.003 and earlier allows remote attackers to gain sensitive information via (1) unexpected characters in the session ID su
СредняяCVSS 5,0Proof of conceptEPSS 7 %phpgroupware · phpgroupware31 дек. 2004 г.
- CVE-2004-257520Наблюдать
phpGroupWare 0.9.14.005 and earlier allow remote attackers to obtain sensitive information via a direct request to (1) hook_admin.inc.php, (
СредняяCVSS 5,0Эксплойта нетEPSS 2 %phpgroupware · phpgroupware31 дек. 2004 г.
- CVE-2004-257620Наблюдать
class.vfs_dav.inc.php in phpGroupWare 0.9.16.000 does not create .htaccess files to enable authorization checks for access to users' home-di
СредняяCVSS 5,0Эксплойта нетEPSS 2 %phpgroupware · phpgroupware31 дек. 2004 г.
- CVE-2004-257820Наблюдать
phpGroupWare before 0.9.16.002 transmits the (1) header admin and (2) setup passwords in plaintext via cookies, which allows remote attacker
СредняяCVSS 5,0Эксплойта нетEPSS 1 %phpgroupware · phpgroupware31 дек. 2004 г.
- CVE-2004-257720Наблюдать
The acl_check function in phpGroupWare 0.9.16RC2 always returns True, even when mkdir does not behave as expected, which could allow remote
СредняяCVSS 5,0Эксплойта нетEPSS 1 %phpgroupware · phpgroupware31 дек. 2004 г.
- CVE-2004-138418Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in phpGroupWare 0.9.16.003 and earlier allow remote attackers to inject arbitrary web sc
СредняяCVSS 4,3Proof of conceptEPSS 4 %phpgroupware · phpgroupware31 дек. 2004 г.
- CVE-2004-257418Наблюдать
Cross-site scripting (XSS) vulnerability in index.php in phpGroupWare 0.9.14.005 and earlier allows remote attackers to inject arbitrary web
СредняяCVSS 4,3Proof of conceptEPSS 4 %phpgroupware · phpgroupware31 дек. 2004 г.
- CVE-2009-441618Наблюдать
Cross-site scripting (XSS) vulnerability in login.php in phpGroupWare 0.9.16.12, and possibly other versions before 0.9.16.014, allows remot
СредняяCVSS 4,3Эксплойта нетEPSS 2 %phpgroupware · phpgroupware24 дек. 2009 г.