phpgroupware records
27 published records for vendor phpgroupware.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 7
- With a fix record
- 44.4%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Recurring classes
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
27 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
41Plan | CVE-2001-0043No exploit | phpGroupWare before 0.9.7 allows remote attackers to execute arbitrary PHP commands by specifying a malicious include file in the phpgw_infophpgroupware · phpgroupware | Critical10.0 | — | 3.1% | Feb 16, 2001 |
41Plan | CVE-2003-0599No exploit | Unknown vulnerability in the Virtual File System (VFS) capability for phpGroupWare 0.9.16preRC and versions before 0.9.14.004 with unknown iphpgroupware · phpgroupware | Critical10.0 | — | 1.8% | Aug 27, 2003 |
40Plan | CVE-2004-2407No exploit | Unknown vulnerability in phpGroupWare before 0.9.14.002 has unknown attack vectors and impact, related to a "security hole" in the Setup/Conphpgroupware · phpgroupware | Critical10.0 | — | 1.5% | Dec 31, 2004 |
40Plan | CVE-2004-2406No exploit | Unknown "overflow" in the phpgw_config table for phpGroupWare before 0.9.14.002 has unknown attack vectors and impact.phpgroupware · phpgroupware | Critical10.0 | — | 1.4% | Dec 31, 2004 |
31Monitor | CVE-2009-4415No exploit | Multiple directory traversal vulnerabilities in phpGroupWare 0.9.16.12, and possibly other versions before 0.9.16.014, allow remote attackerphpgroupware · phpgroupware · CWE-22 | High7.5 | — | 3.4% | Dec 24, 2009 |
31Monitor | CVE-2004-1383Proof of concept | Multiple SQL injection vulnerabilities in phpGroupWare 0.9.16.003 and earlier allow remote attackers to execute arbitrary SQL statements viaphpgroupware · phpgroupware | High7.5 | — | 2.8% | Dec 31, 2004 |
31Monitor | CVE-2004-2573Proof of concept | PHP remote file inclusion vulnerability in tables_update.inc.php in phpGroupWare 0.9.14.005 and earlier allows remote attackers to execute aphpgroupware · phpgroupware | High7.5 | — | 2.6% | Dec 31, 2004 |
31Monitor | CVE-2002-0536Proof of concept | PHPGroupware 0.9.12 and earlier, when running with the magic_quotes_gpc feature disabled, allows remote attackers to compromise the databasephpgroupware · phpgroupware | High7.5 | — | 2.5% | Jul 3, 2002 |
31Monitor | CVE-2010-0404No exploit | Multiple SQL injection vulnerabilities in phpGroupWare (phpgw) before 0.9.16.016 allow remote attackers to execute arbitrary SQL commands viphpgroupware · phpgroupware · CWE-89 | High7.5 | — | 2.3% | May 19, 2010 |
30Monitor | CVE-2004-0016No exploit | The calendar module for phpgroupware 0.9.14 does not enforce the "save extension" feature for holiday files, which allows remote attackers tphpgroupware · phpgroupware | High7.5 | — | 1.6% | Feb 3, 2004 |
30Monitor | CVE-2003-0657No exploit | Multiple SQL injection vulnerabilities in the infolog module for phpgroupware 0.9.14 and earlier could allow remote attackers to conduct unaphpgroupware · phpgroupware | High7.5 | — | 1.3% | Aug 27, 2003 |
30Monitor | CVE-2004-0017No exploit | Multiple SQL injection vulnerabilities in the (1) calendar and (2) infolog modules for phpgroupware 0.9.14 allow remote attackers to performphpgroupware · phpgroupware | High7.5 | — | 1.2% | Feb 3, 2004 |
28Monitor | CVE-2005-3347No exploit | Multiple directory traversal vulnerabilities in index.php in phpSysInfo 2.4 and earlier, as used in phpgroupware 0.9.16 and earlier, and egrphpgroupware · phpgroupware · CWE-22 | Medium6.8 | — | 3.5% | Nov 17, 2005 |
28Monitor | CVE-2010-0403No exploit | Directory traversal vulnerability in about.php in phpGroupWare (phpgw) before 0.9.16.016 allows remote attackers to include and execute arbiphpgroupware · phpgroupware · CWE-22 | Medium6.8 | — | 2.0% | May 19, 2010 |
27Monitor | CVE-2004-0875No exploit | Multiple cross-site scripting (XSS) vulnerabilities in Phpgroupware (aka webdistro) 0.9.16.002 and earlier allow remote attackers to insert phpgroupware · phpgroupware | Medium6.8 | — | 1.3% | Dec 23, 2004 |
27Monitor | CVE-2009-4414No exploit | SQL injection vulnerability in phpgwapi /inc/class.auth_sql.inc.php in phpGroupWare 0.9.16.12, and possibly other versions before 0.9.16.014phpgroupware · phpgroupware · CWE-89 | Medium6.8 | — | 1.3% | Dec 24, 2009 |
26Monitor | CVE-2006-4458Proof of concept | Directory traversal vulnerability in calendar/inc/class.holidaycalc.inc.php in phpGroupWare 0.9.16.010 and earlier allows remote attackers tphpgroupware · phpgroupware | Medium6.4 | — | 3.3% | Aug 31, 2006 |
22Monitor | CVE-2004-1385Proof of concept | phpGroupWare 0.9.16.003 and earlier allows remote attackers to gain sensitive information via (1) unexpected characters in the session ID suphpgroupware · phpgroupware | Medium5.0 | — | 7.3% | Dec 31, 2004 |
20Monitor | CVE-2004-2575No exploit | phpGroupWare 0.9.14.005 and earlier allow remote attackers to obtain sensitive information via a direct request to (1) hook_admin.inc.php, (phpgroupware · phpgroupware | Medium5.0 | — | 1.5% | Dec 31, 2004 |
20Monitor | CVE-2004-2576No exploit | class.vfs_dav.inc.php in phpGroupWare 0.9.16.000 does not create .htaccess files to enable authorization checks for access to users' home-diphpgroupware · phpgroupware | Medium5.0 | — | 1.5% | Dec 31, 2004 |
20Monitor | CVE-2004-2578No exploit | phpGroupWare before 0.9.16.002 transmits the (1) header admin and (2) setup passwords in plaintext via cookies, which allows remote attackerphpgroupware · phpgroupware | Medium5.0 | — | 1.4% | Dec 31, 2004 |
20Monitor | CVE-2004-2577No exploit | The acl_check function in phpGroupWare 0.9.16RC2 always returns True, even when mkdir does not behave as expected, which could allow remote phpgroupware · phpgroupware | Medium5.0 | — | 1.4% | Dec 31, 2004 |
18Monitor | CVE-2004-1384Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in phpGroupWare 0.9.16.003 and earlier allow remote attackers to inject arbitrary web scphpgroupware · phpgroupware | Medium4.3 | — | 4.0% | Dec 31, 2004 |
18Monitor | CVE-2004-2574Proof of concept | Cross-site scripting (XSS) vulnerability in index.php in phpGroupWare 0.9.14.005 and earlier allows remote attackers to inject arbitrary webphpgroupware · phpgroupware | Medium4.3 | — | 3.6% | Dec 31, 2004 |
18Monitor | CVE-2009-4416No exploit | Cross-site scripting (XSS) vulnerability in login.php in phpGroupWare 0.9.16.12, and possibly other versions before 0.9.16.014, allows remotphpgroupware · phpgroupware · CWE-79 | Medium4.3 | — | 2.3% | Dec 24, 2009 |
- CVE-2001-004341Plan
phpGroupWare before 0.9.7 allows remote attackers to execute arbitrary PHP commands by specifying a malicious include file in the phpgw_info
CriticalCVSS 10.0No exploitEPSS 3%phpgroupware · phpgroupwareFeb 16, 2001
- CVE-2003-059941Plan
Unknown vulnerability in the Virtual File System (VFS) capability for phpGroupWare 0.9.16preRC and versions before 0.9.14.004 with unknown i
CriticalCVSS 10.0No exploitEPSS 2%phpgroupware · phpgroupwareAug 27, 2003
- CVE-2004-240740Plan
Unknown vulnerability in phpGroupWare before 0.9.14.002 has unknown attack vectors and impact, related to a "security hole" in the Setup/Con
CriticalCVSS 10.0No exploitEPSS 1%phpgroupware · phpgroupwareDec 31, 2004
- CVE-2004-240640Plan
Unknown "overflow" in the phpgw_config table for phpGroupWare before 0.9.14.002 has unknown attack vectors and impact.
CriticalCVSS 10.0No exploitEPSS 1%phpgroupware · phpgroupwareDec 31, 2004
- CVE-2009-441531Monitor
Multiple directory traversal vulnerabilities in phpGroupWare 0.9.16.12, and possibly other versions before 0.9.16.014, allow remote attacker
HighCVSS 7.5No exploitEPSS 3%phpgroupware · phpgroupwareDec 24, 2009
- CVE-2004-138331Monitor
Multiple SQL injection vulnerabilities in phpGroupWare 0.9.16.003 and earlier allow remote attackers to execute arbitrary SQL statements via
HighCVSS 7.5Proof of conceptEPSS 3%phpgroupware · phpgroupwareDec 31, 2004
- CVE-2004-257331Monitor
PHP remote file inclusion vulnerability in tables_update.inc.php in phpGroupWare 0.9.14.005 and earlier allows remote attackers to execute a
HighCVSS 7.5Proof of conceptEPSS 3%phpgroupware · phpgroupwareDec 31, 2004
- CVE-2002-053631Monitor
PHPGroupware 0.9.12 and earlier, when running with the magic_quotes_gpc feature disabled, allows remote attackers to compromise the database
HighCVSS 7.5Proof of conceptEPSS 3%phpgroupware · phpgroupwareJul 3, 2002
- CVE-2010-040431Monitor
Multiple SQL injection vulnerabilities in phpGroupWare (phpgw) before 0.9.16.016 allow remote attackers to execute arbitrary SQL commands vi
HighCVSS 7.5No exploitEPSS 2%phpgroupware · phpgroupwareMay 19, 2010
- CVE-2004-001630Monitor
The calendar module for phpgroupware 0.9.14 does not enforce the "save extension" feature for holiday files, which allows remote attackers t
HighCVSS 7.5No exploitEPSS 2%phpgroupware · phpgroupwareFeb 3, 2004
- CVE-2003-065730Monitor
Multiple SQL injection vulnerabilities in the infolog module for phpgroupware 0.9.14 and earlier could allow remote attackers to conduct una
HighCVSS 7.5No exploitEPSS 1%phpgroupware · phpgroupwareAug 27, 2003
- CVE-2004-001730Monitor
Multiple SQL injection vulnerabilities in the (1) calendar and (2) infolog modules for phpgroupware 0.9.14 allow remote attackers to perform
HighCVSS 7.5No exploitEPSS 1%phpgroupware · phpgroupwareFeb 3, 2004
- CVE-2005-334728Monitor
Multiple directory traversal vulnerabilities in index.php in phpSysInfo 2.4 and earlier, as used in phpgroupware 0.9.16 and earlier, and egr
MediumCVSS 6.8No exploitEPSS 4%phpgroupware · phpgroupwareNov 17, 2005
- CVE-2010-040328Monitor
Directory traversal vulnerability in about.php in phpGroupWare (phpgw) before 0.9.16.016 allows remote attackers to include and execute arbi
MediumCVSS 6.8No exploitEPSS 2%phpgroupware · phpgroupwareMay 19, 2010
- CVE-2004-087527Monitor
Multiple cross-site scripting (XSS) vulnerabilities in Phpgroupware (aka webdistro) 0.9.16.002 and earlier allow remote attackers to insert
MediumCVSS 6.8No exploitEPSS 1%phpgroupware · phpgroupwareDec 23, 2004
- CVE-2009-441427Monitor
SQL injection vulnerability in phpgwapi /inc/class.auth_sql.inc.php in phpGroupWare 0.9.16.12, and possibly other versions before 0.9.16.014
MediumCVSS 6.8No exploitEPSS 1%phpgroupware · phpgroupwareDec 24, 2009
- CVE-2006-445826Monitor
Directory traversal vulnerability in calendar/inc/class.holidaycalc.inc.php in phpGroupWare 0.9.16.010 and earlier allows remote attackers t
MediumCVSS 6.4Proof of conceptEPSS 3%phpgroupware · phpgroupwareAug 31, 2006
- CVE-2004-138522Monitor
phpGroupWare 0.9.16.003 and earlier allows remote attackers to gain sensitive information via (1) unexpected characters in the session ID su
MediumCVSS 5.0Proof of conceptEPSS 7%phpgroupware · phpgroupwareDec 31, 2004
- CVE-2004-257520Monitor
phpGroupWare 0.9.14.005 and earlier allow remote attackers to obtain sensitive information via a direct request to (1) hook_admin.inc.php, (
MediumCVSS 5.0No exploitEPSS 2%phpgroupware · phpgroupwareDec 31, 2004
- CVE-2004-257620Monitor
class.vfs_dav.inc.php in phpGroupWare 0.9.16.000 does not create .htaccess files to enable authorization checks for access to users' home-di
MediumCVSS 5.0No exploitEPSS 2%phpgroupware · phpgroupwareDec 31, 2004
- CVE-2004-257820Monitor
phpGroupWare before 0.9.16.002 transmits the (1) header admin and (2) setup passwords in plaintext via cookies, which allows remote attacker
MediumCVSS 5.0No exploitEPSS 1%phpgroupware · phpgroupwareDec 31, 2004
- CVE-2004-257720Monitor
The acl_check function in phpGroupWare 0.9.16RC2 always returns True, even when mkdir does not behave as expected, which could allow remote
MediumCVSS 5.0No exploitEPSS 1%phpgroupware · phpgroupwareDec 31, 2004
- CVE-2004-138418Monitor
Multiple cross-site scripting (XSS) vulnerabilities in phpGroupWare 0.9.16.003 and earlier allow remote attackers to inject arbitrary web sc
MediumCVSS 4.3Proof of conceptEPSS 4%phpgroupware · phpgroupwareDec 31, 2004
- CVE-2004-257418Monitor
Cross-site scripting (XSS) vulnerability in index.php in phpGroupWare 0.9.14.005 and earlier allows remote attackers to inject arbitrary web
MediumCVSS 4.3Proof of conceptEPSS 4%phpgroupware · phpgroupwareDec 31, 2004
- CVE-2009-441618Monitor
Cross-site scripting (XSS) vulnerability in login.php in phpGroupWare 0.9.16.12, and possibly other versions before 0.9.16.014, allows remot
MediumCVSS 4.3No exploitEPSS 2%phpgroupware · phpgroupwareDec 24, 2009