Перейти к содержимому
Noroxi

Записи phpgroupware

27 опубликованных записей вендора phpgroupware.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
7
С записью об исправлении
44,4 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Записи по годам

    Столбик: всего · тёмная часть: CISA KEV.

    Повторяющиеся классы

    Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.

    CWE

    Все записи

    27 записей
    • CVE-2001-0043
      41В плане

      phpGroupWare before 0.9.7 allows remote attackers to execute arbitrary PHP commands by specifying a malicious include file in the phpgw_info

      КритическаяCVSS 10,0Эксплойта нетEPSS 3 %

      phpgroupware · phpgroupware16 февр. 2001 г.

    • CVE-2003-0599
      41В плане

      Unknown vulnerability in the Virtual File System (VFS) capability for phpGroupWare 0.9.16preRC and versions before 0.9.14.004 with unknown i

      КритическаяCVSS 10,0Эксплойта нетEPSS 2 %

      phpgroupware · phpgroupware27 авг. 2003 г.

    • CVE-2004-2407
      40В плане

      Unknown vulnerability in phpGroupWare before 0.9.14.002 has unknown attack vectors and impact, related to a "security hole" in the Setup/Con

      КритическаяCVSS 10,0Эксплойта нетEPSS 1 %

      phpgroupware · phpgroupware31 дек. 2004 г.

    • CVE-2004-2406
      40В плане

      Unknown "overflow" in the phpgw_config table for phpGroupWare before 0.9.14.002 has unknown attack vectors and impact.

      КритическаяCVSS 10,0Эксплойта нетEPSS 1 %

      phpgroupware · phpgroupware31 дек. 2004 г.

    • CVE-2009-4415
      31Наблюдать

      Multiple directory traversal vulnerabilities in phpGroupWare 0.9.16.12, and possibly other versions before 0.9.16.014, allow remote attacker

      ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %

      phpgroupware · phpgroupware24 дек. 2009 г.

    • CVE-2004-1383
      31Наблюдать

      Multiple SQL injection vulnerabilities in phpGroupWare 0.9.16.003 and earlier allow remote attackers to execute arbitrary SQL statements via

      ВысокаяCVSS 7,5Proof of conceptEPSS 3 %

      phpgroupware · phpgroupware31 дек. 2004 г.

    • CVE-2004-2573
      31Наблюдать

      PHP remote file inclusion vulnerability in tables_update.inc.php in phpGroupWare 0.9.14.005 and earlier allows remote attackers to execute a

      ВысокаяCVSS 7,5Proof of conceptEPSS 3 %

      phpgroupware · phpgroupware31 дек. 2004 г.

    • CVE-2002-0536
      31Наблюдать

      PHPGroupware 0.9.12 and earlier, when running with the magic_quotes_gpc feature disabled, allows remote attackers to compromise the database

      ВысокаяCVSS 7,5Proof of conceptEPSS 3 %

      phpgroupware · phpgroupware3 июл. 2002 г.

    • CVE-2010-0404
      31Наблюдать

      Multiple SQL injection vulnerabilities in phpGroupWare (phpgw) before 0.9.16.016 allow remote attackers to execute arbitrary SQL commands vi

      ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

      phpgroupware · phpgroupware19 мая 2010 г.

    • CVE-2004-0016
      30Наблюдать

      The calendar module for phpgroupware 0.9.14 does not enforce the "save extension" feature for holiday files, which allows remote attackers t

      ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

      phpgroupware · phpgroupware3 февр. 2004 г.

    • CVE-2003-0657
      30Наблюдать

      Multiple SQL injection vulnerabilities in the infolog module for phpgroupware 0.9.14 and earlier could allow remote attackers to conduct una

      ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

      phpgroupware · phpgroupware27 авг. 2003 г.

    • CVE-2004-0017
      30Наблюдать

      Multiple SQL injection vulnerabilities in the (1) calendar and (2) infolog modules for phpgroupware 0.9.14 allow remote attackers to perform

      ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

      phpgroupware · phpgroupware3 февр. 2004 г.

    • CVE-2005-3347
      28Наблюдать

      Multiple directory traversal vulnerabilities in index.php in phpSysInfo 2.4 and earlier, as used in phpgroupware 0.9.16 and earlier, and egr

      СредняяCVSS 6,8Эксплойта нетEPSS 4 %

      phpgroupware · phpgroupware17 нояб. 2005 г.

    • CVE-2010-0403
      28Наблюдать

      Directory traversal vulnerability in about.php in phpGroupWare (phpgw) before 0.9.16.016 allows remote attackers to include and execute arbi

      СредняяCVSS 6,8Эксплойта нетEPSS 2 %

      phpgroupware · phpgroupware19 мая 2010 г.

    • CVE-2004-0875
      27Наблюдать

      Multiple cross-site scripting (XSS) vulnerabilities in Phpgroupware (aka webdistro) 0.9.16.002 and earlier allow remote attackers to insert

      СредняяCVSS 6,8Эксплойта нетEPSS 1 %

      phpgroupware · phpgroupware23 дек. 2004 г.

    • CVE-2009-4414
      27Наблюдать

      SQL injection vulnerability in phpgwapi /inc/class.auth_sql.inc.php in phpGroupWare 0.9.16.12, and possibly other versions before 0.9.16.014

      СредняяCVSS 6,8Эксплойта нетEPSS 1 %

      phpgroupware · phpgroupware24 дек. 2009 г.

    • CVE-2006-4458
      26Наблюдать

      Directory traversal vulnerability in calendar/inc/class.holidaycalc.inc.php in phpGroupWare 0.9.16.010 and earlier allows remote attackers t

      СредняяCVSS 6,4Proof of conceptEPSS 3 %

      phpgroupware · phpgroupware31 авг. 2006 г.

    • CVE-2004-1385
      22Наблюдать

      phpGroupWare 0.9.16.003 and earlier allows remote attackers to gain sensitive information via (1) unexpected characters in the session ID su

      СредняяCVSS 5,0Proof of conceptEPSS 7 %

      phpgroupware · phpgroupware31 дек. 2004 г.

    • CVE-2004-2575
      20Наблюдать

      phpGroupWare 0.9.14.005 and earlier allow remote attackers to obtain sensitive information via a direct request to (1) hook_admin.inc.php, (

      СредняяCVSS 5,0Эксплойта нетEPSS 2 %

      phpgroupware · phpgroupware31 дек. 2004 г.

    • CVE-2004-2576
      20Наблюдать

      class.vfs_dav.inc.php in phpGroupWare 0.9.16.000 does not create .htaccess files to enable authorization checks for access to users' home-di

      СредняяCVSS 5,0Эксплойта нетEPSS 2 %

      phpgroupware · phpgroupware31 дек. 2004 г.

    • CVE-2004-2578
      20Наблюдать

      phpGroupWare before 0.9.16.002 transmits the (1) header admin and (2) setup passwords in plaintext via cookies, which allows remote attacker

      СредняяCVSS 5,0Эксплойта нетEPSS 1 %

      phpgroupware · phpgroupware31 дек. 2004 г.

    • CVE-2004-2577
      20Наблюдать

      The acl_check function in phpGroupWare 0.9.16RC2 always returns True, even when mkdir does not behave as expected, which could allow remote

      СредняяCVSS 5,0Эксплойта нетEPSS 1 %

      phpgroupware · phpgroupware31 дек. 2004 г.

    • CVE-2004-1384
      18Наблюдать

      Multiple cross-site scripting (XSS) vulnerabilities in phpGroupWare 0.9.16.003 and earlier allow remote attackers to inject arbitrary web sc

      СредняяCVSS 4,3Proof of conceptEPSS 4 %

      phpgroupware · phpgroupware31 дек. 2004 г.

    • CVE-2004-2574
      18Наблюдать

      Cross-site scripting (XSS) vulnerability in index.php in phpGroupWare 0.9.14.005 and earlier allows remote attackers to inject arbitrary web

      СредняяCVSS 4,3Proof of conceptEPSS 4 %

      phpgroupware · phpgroupware31 дек. 2004 г.

    • CVE-2009-4416
      18Наблюдать

      Cross-site scripting (XSS) vulnerability in login.php in phpGroupWare 0.9.16.12, and possibly other versions before 0.9.16.014, allows remot

      СредняяCVSS 4,3Эксплойта нетEPSS 2 %

      phpgroupware · phpgroupware24 дек. 2009 г.