EGroupware kayıtları
egroupware üreticisine ait 25 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 6
- Düzeltme kaydı olan
- %24
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')7
- CWE-94 Improper Control of Generation of Code ('Code Injection')4
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')3
- CWE-203 Observable Discrepancy1
- CWE-522 Insufficiently Protected Credentials1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
25 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
41Planlayın | CVE-2007-3154İstismar yok | Unspecified vulnerability in Walter Zorn wz_tooltip.js (aka wz_tooltips) before 4.01, as used by eGroupWare before 1.2.107-2 and other packaegroupware · egroupware | Kritik10,0 | — | %1,9 | 11 Haz 2007 |
41Planlayın | CVE-2007-3155İstismar yok | Unspecified vulnerability in eGroupWare before 1.2.107-2 has unknown impact and attack vectors related to ADOdb.egroupware · egroupware | Kritik10,0 | — | %1,8 | 11 Haz 2007 |
40Planlayın | CVE-2008-2041İstismar yok | Multiple unspecified vulnerabilities in eGroupWare before 1.4.004 have unspecified attack vectors and "grave" impact when the web server hasegroupware · egroupware · CWE-94 | Kritik10,0 | — | %1,6 | 30 Nis 2008 |
39İzleyin | CVE-2024-40614İstismar yok | EGroupware before 23.1.20240624 mishandles an ORDER BY clause.egroupware · egroupware · CWE-89 | Kritik9,8 | — | %0,7 | 7 Tem 2024 |
35İzleyin | CVE-2014-2988İstismar yok | EGroupware Enterprise Line (EPL) before 1.1.20140505, EGroupware Community Edition before 1.8.007.20140506, and EGroupware before 14.1 beta egroupware · egroupware · CWE-94 | Yüksek8,5 | — | %1,8 | 26 Eki 2014 |
34İzleyin | CVE-2026-22243Kavram kanıtı | EGroupware has SQL Injection in Nextmatch Filter Processingegroupware · egroupware · CWE-89 | Yüksek8,7 | — | %0,4 | 28 Oca 2026 |
33İzleyin | CVE-2010-3313Kavram kanıtı | phpgwapi/js/fckeditor/editor/dialog/fck_spellerpages/spellerpages/serverscripts/spellchecker.php in EGroupware 1.4.001+.002; 1.6.001+.002 anegroupware · egroupware · CWE-94 | Yüksek7,5 | — | %8,5 | 22 Eyl 2010 |
31İzleyin | CVE-2014-2027İstismar yok | eGroupware before 1.8.006.20140217 allows remote attackers to conduct PHP object injection attacks, delete arbitrary files, and possibly exeegroupware · egroupware · CWE-94 | Yüksek7,5 | — | %4,1 | 31 Mar 2015 |
31İzleyin | CVE-2005-1203Kavram kanıtı | Multiple SQL injection vulnerabilities in index.php in eGroupware before 1.0.0.007 allow remote attackers to execute arbitrary SQL commands egroupware · egroupware | Yüksek7,5 | — | %3,2 | 2 May 2005 |
30İzleyin | CVE-2011-4949İstismar yok | SQL injection vulnerability in phpgwapi/js/dhtmlxtree/samples/with_db/loaddetails.php in EGroupware Enterprise Line (EPL) before 11.1.201108egroupware · egroupware · CWE-89 | Yüksek7,5 | — | %1,5 | 31 Ağu 2012 |
28İzleyin | CVE-2005-1202Kavram kanıtı | Multiple cross-site scripting (XSS) vulnerabilities in eGroupware before 1.0.0.007 allow remote attackers to inject arbitrary web script or egroupware · egroupware | Orta6,8 | — | %3,0 | 2 May 2005 |
27İzleyin | CVE-2014-2987Kavram kanıtı | Multiple cross-site request forgery (CSRF) vulnerabilities in EGroupware Enterprise Line (EPL) before 1.1.20140505, EGroupware Community Ediegroupware · egroupware · CWE-352 | Orta6,8 | — | %1,4 | 26 Eki 2014 |
24İzleyin | CVE-2017-14920İstismar yok | Stored XSS vulnerability in eGroupware Community Edition before 16.1.20170922 allows an unauthenticated remote attacker to inject JavaScriptegroupware · egroupware · CWE-79 | Orta6,1 | — | %1,1 | 29 Eyl 2017 |
24İzleyin | CVE-2023-38329İstismar yok | An issue was discovered in eGroupWare 17.1.20190111.egroupware · egroupware · CWE-79 | Orta6,1 | — | %0,2 | 11 Tem 2025 |
23İzleyin | CVE-2011-4951İstismar yok | Open redirect vulnerability in phpgwapi/ntlm/index.php in EGroupware Enterprise Line (EPL) before 11.1.20110804-1 and EGroupware Community Eegroupware · egroupware | Orta5,8 | — | %1,5 | 31 Ağu 2012 |
21İzleyin | CVE-2011-4948İstismar yok | Directory traversal vulnerability in admin/remote.php in EGroupware Enterprise Line (EPL) before 11.1.20110804-1 and EGroupware Community Edegroupware · egroupware · CWE-22 | Orta5,0 | — | %2,3 | 31 Ağu 2012 |
21İzleyin | CVE-2023-38327İstismar yok | An issue was discovered in eGroupWare 17.1.20190111.egroupware · egroupware · CWE-203 | Orta5,3 | — | %0,3 | 11 Tem 2025 |
20İzleyin | CVE-2008-1502İstismar yok | The _bad_protocol_once function in phpgwapi/inc/class.kses.inc.php in KSES, as used in eGroupWare before 1.4.003, Moodle before 1.8.5, and oegroupware · egroupware · CWE-79 | Orta4,3 | — | %10,5 | 25 Mar 2008 |
19İzleyin | CVE-2023-38328İstismar yok | An issue was discovered in eGroupWare 17.1.20190111.egroupware · egroupware · CWE-522 | Orta4,9 | — | %0,6 | 26 Eki 2023 |
18İzleyin | CVE-2004-1467Kavram kanıtı | Multiple cross-site scripting (XSS) vulnerabilities in eGroupWare 1.0.00.003 and earlier allow remote attackers to inject arbitrary web scriegroupware · egroupware | Orta4,3 | — | %3,6 | 31 Ara 2004 |
18İzleyin | CVE-2010-3314Kavram kanıtı | Cross-site scripting (XSS) vulnerability in login.php in EGroupware 1.4.001+.002; 1.6.001+.002 and possibly other versions before 1.6.003; aegroupware · egroupware · CWE-79 | Orta4,3 | — | %3,3 | 22 Eyl 2010 |
17İzleyin | CVE-2011-4950İstismar yok | Cross-site scripting (XSS) vulnerability in phpgwapi/js/jscalendar/test.php in EGroupware Enterprise Line (EPL) before 11.1.20110804-1 and Eegroupware · egroupware · CWE-79 | Orta4,3 | — | %1,4 | 31 Ağu 2012 |
17İzleyin | CVE-2012-2211İstismar yok | Cross-site scripting (XSS) vulnerability in phpgwapi/inc/common_functions_inc.php in eGroupware before 1.8.004.20120405 allows remote attackegroupware · egroupware · CWE-79 | Orta4,3 | — | %1,2 | 22 Kas 2012 |
17İzleyin | CVE-2007-5091İstismar yok | Multiple cross-site scripting (XSS) vulnerabilities in eGroupWare 1.4.001 allow remote attackers to inject arbitrary web script or HTML via egroupware · egroupware · CWE-79 | Orta4,3 | — | %1,1 | 26 Eyl 2007 |
8İzleyin | CVE-2005-1129İstismar yok | eGroupWare 1.0.6 and earlier, when an e-mail is composed with an attachment but not sent, will send that attachment in the next e-mail, whicegroupware · egroupware | Düşük2,1 | — | %0,4 | 2 May 2005 |
- CVE-2007-315441Planlayın
Unspecified vulnerability in Walter Zorn wz_tooltip.js (aka wz_tooltips) before 4.01, as used by eGroupWare before 1.2.107-2 and other packa
KritikCVSS 10,0İstismar yokEPSS %2egroupware · egroupware11 Haz 2007
- CVE-2007-315541Planlayın
Unspecified vulnerability in eGroupWare before 1.2.107-2 has unknown impact and attack vectors related to ADOdb.
KritikCVSS 10,0İstismar yokEPSS %2egroupware · egroupware11 Haz 2007
- CVE-2008-204140Planlayın
Multiple unspecified vulnerabilities in eGroupWare before 1.4.004 have unspecified attack vectors and "grave" impact when the web server has
KritikCVSS 10,0İstismar yokEPSS %2egroupware · egroupware30 Nis 2008
- CVE-2024-4061439İzleyin
EGroupware before 23.1.20240624 mishandles an ORDER BY clause.
KritikCVSS 9,8İstismar yokEPSS %1egroupware · egroupware7 Tem 2024
- CVE-2014-298835İzleyin
EGroupware Enterprise Line (EPL) before 1.1.20140505, EGroupware Community Edition before 1.8.007.20140506, and EGroupware before 14.1 beta
YüksekCVSS 8,5İstismar yokEPSS %2egroupware · egroupware26 Eki 2014
- CVE-2026-2224334İzleyin
EGroupware has SQL Injection in Nextmatch Filter Processing
YüksekCVSS 8,7Kavram kanıtıEPSS %0egroupware · egroupware28 Oca 2026
- CVE-2010-331333İzleyin
phpgwapi/js/fckeditor/editor/dialog/fck_spellerpages/spellerpages/serverscripts/spellchecker.php in EGroupware 1.4.001+.002; 1.6.001+.002 an
YüksekCVSS 7,5Kavram kanıtıEPSS %9egroupware · egroupware22 Eyl 2010
- CVE-2014-202731İzleyin
eGroupware before 1.8.006.20140217 allows remote attackers to conduct PHP object injection attacks, delete arbitrary files, and possibly exe
YüksekCVSS 7,5İstismar yokEPSS %4egroupware · egroupware31 Mar 2015
- CVE-2005-120331İzleyin
Multiple SQL injection vulnerabilities in index.php in eGroupware before 1.0.0.007 allow remote attackers to execute arbitrary SQL commands
YüksekCVSS 7,5Kavram kanıtıEPSS %3egroupware · egroupware2 May 2005
- CVE-2011-494930İzleyin
SQL injection vulnerability in phpgwapi/js/dhtmlxtree/samples/with_db/loaddetails.php in EGroupware Enterprise Line (EPL) before 11.1.201108
YüksekCVSS 7,5İstismar yokEPSS %2egroupware · egroupware31 Ağu 2012
- CVE-2005-120228İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in eGroupware before 1.0.0.007 allow remote attackers to inject arbitrary web script or
OrtaCVSS 6,8Kavram kanıtıEPSS %3egroupware · egroupware2 May 2005
- CVE-2014-298727İzleyin
Multiple cross-site request forgery (CSRF) vulnerabilities in EGroupware Enterprise Line (EPL) before 1.1.20140505, EGroupware Community Edi
OrtaCVSS 6,8Kavram kanıtıEPSS %1egroupware · egroupware26 Eki 2014
- CVE-2017-1492024İzleyin
Stored XSS vulnerability in eGroupware Community Edition before 16.1.20170922 allows an unauthenticated remote attacker to inject JavaScript
OrtaCVSS 6,1İstismar yokEPSS %1egroupware · egroupware29 Eyl 2017
- CVE-2023-3832924İzleyin
An issue was discovered in eGroupWare 17.1.20190111.
OrtaCVSS 6,1İstismar yokEPSS %0egroupware · egroupware11 Tem 2025
- CVE-2011-495123İzleyin
Open redirect vulnerability in phpgwapi/ntlm/index.php in EGroupware Enterprise Line (EPL) before 11.1.20110804-1 and EGroupware Community E
OrtaCVSS 5,8İstismar yokEPSS %1egroupware · egroupware31 Ağu 2012
- CVE-2011-494821İzleyin
Directory traversal vulnerability in admin/remote.php in EGroupware Enterprise Line (EPL) before 11.1.20110804-1 and EGroupware Community Ed
OrtaCVSS 5,0İstismar yokEPSS %2egroupware · egroupware31 Ağu 2012
- CVE-2023-3832721İzleyin
An issue was discovered in eGroupWare 17.1.20190111.
OrtaCVSS 5,3İstismar yokEPSS %0egroupware · egroupware11 Tem 2025
- CVE-2008-150220İzleyin
The _bad_protocol_once function in phpgwapi/inc/class.kses.inc.php in KSES, as used in eGroupWare before 1.4.003, Moodle before 1.8.5, and o
OrtaCVSS 4,3İstismar yokEPSS %11egroupware · egroupware25 Mar 2008
- CVE-2023-3832819İzleyin
An issue was discovered in eGroupWare 17.1.20190111.
OrtaCVSS 4,9İstismar yokEPSS %1egroupware · egroupware26 Eki 2023
- CVE-2004-146718İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in eGroupWare 1.0.00.003 and earlier allow remote attackers to inject arbitrary web scri
OrtaCVSS 4,3Kavram kanıtıEPSS %4egroupware · egroupware31 Ara 2004
- CVE-2010-331418İzleyin
Cross-site scripting (XSS) vulnerability in login.php in EGroupware 1.4.001+.002; 1.6.001+.002 and possibly other versions before 1.6.003; a
OrtaCVSS 4,3Kavram kanıtıEPSS %3egroupware · egroupware22 Eyl 2010
- CVE-2011-495017İzleyin
Cross-site scripting (XSS) vulnerability in phpgwapi/js/jscalendar/test.php in EGroupware Enterprise Line (EPL) before 11.1.20110804-1 and E
OrtaCVSS 4,3İstismar yokEPSS %1egroupware · egroupware31 Ağu 2012
- CVE-2012-221117İzleyin
Cross-site scripting (XSS) vulnerability in phpgwapi/inc/common_functions_inc.php in eGroupware before 1.8.004.20120405 allows remote attack
OrtaCVSS 4,3İstismar yokEPSS %1egroupware · egroupware22 Kas 2012
- CVE-2007-509117İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in eGroupWare 1.4.001 allow remote attackers to inject arbitrary web script or HTML via
OrtaCVSS 4,3İstismar yokEPSS %1egroupware · egroupware26 Eyl 2007
- CVE-2005-11298İzleyin
eGroupWare 1.0.6 and earlier, when an e-mail is composed with an attachment but not sent, will send that attachment in the next e-mail, whic
DüşükCVSS 2,1İstismar yokEPSS %0egroupware · egroupware2 May 2005