İçeriğe atla
Noroxi

phpgroupware kayıtları

phpgroupware üreticisine ait 27 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
7
Düzeltme kaydı olan
%44,4
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

27 kayıt
  • CVE-2001-0043
    41Planlayın

    phpGroupWare before 0.9.7 allows remote attackers to execute arbitrary PHP commands by specifying a malicious include file in the phpgw_info

    KritikCVSS 10,0İstismar yokEPSS %3

    phpgroupware · phpgroupware16 Şub 2001

  • CVE-2003-0599
    41Planlayın

    Unknown vulnerability in the Virtual File System (VFS) capability for phpGroupWare 0.9.16preRC and versions before 0.9.14.004 with unknown i

    KritikCVSS 10,0İstismar yokEPSS %2

    phpgroupware · phpgroupware27 Ağu 2003

  • CVE-2004-2407
    40Planlayın

    Unknown vulnerability in phpGroupWare before 0.9.14.002 has unknown attack vectors and impact, related to a "security hole" in the Setup/Con

    KritikCVSS 10,0İstismar yokEPSS %1

    phpgroupware · phpgroupware31 Ara 2004

  • CVE-2004-2406
    40Planlayın

    Unknown "overflow" in the phpgw_config table for phpGroupWare before 0.9.14.002 has unknown attack vectors and impact.

    KritikCVSS 10,0İstismar yokEPSS %1

    phpgroupware · phpgroupware31 Ara 2004

  • CVE-2009-4415
    31İzleyin

    Multiple directory traversal vulnerabilities in phpGroupWare 0.9.16.12, and possibly other versions before 0.9.16.014, allow remote attacker

    YüksekCVSS 7,5İstismar yokEPSS %3

    phpgroupware · phpgroupware24 Ara 2009

  • CVE-2004-1383
    31İzleyin

    Multiple SQL injection vulnerabilities in phpGroupWare 0.9.16.003 and earlier allow remote attackers to execute arbitrary SQL statements via

    YüksekCVSS 7,5Kavram kanıtıEPSS %3

    phpgroupware · phpgroupware31 Ara 2004

  • CVE-2004-2573
    31İzleyin

    PHP remote file inclusion vulnerability in tables_update.inc.php in phpGroupWare 0.9.14.005 and earlier allows remote attackers to execute a

    YüksekCVSS 7,5Kavram kanıtıEPSS %3

    phpgroupware · phpgroupware31 Ara 2004

  • CVE-2002-0536
    31İzleyin

    PHPGroupware 0.9.12 and earlier, when running with the magic_quotes_gpc feature disabled, allows remote attackers to compromise the database

    YüksekCVSS 7,5Kavram kanıtıEPSS %3

    phpgroupware · phpgroupware3 Tem 2002

  • CVE-2010-0404
    31İzleyin

    Multiple SQL injection vulnerabilities in phpGroupWare (phpgw) before 0.9.16.016 allow remote attackers to execute arbitrary SQL commands vi

    YüksekCVSS 7,5İstismar yokEPSS %2

    phpgroupware · phpgroupware19 May 2010

  • CVE-2004-0016
    30İzleyin

    The calendar module for phpgroupware 0.9.14 does not enforce the "save extension" feature for holiday files, which allows remote attackers t

    YüksekCVSS 7,5İstismar yokEPSS %2

    phpgroupware · phpgroupware3 Şub 2004

  • CVE-2003-0657
    30İzleyin

    Multiple SQL injection vulnerabilities in the infolog module for phpgroupware 0.9.14 and earlier could allow remote attackers to conduct una

    YüksekCVSS 7,5İstismar yokEPSS %1

    phpgroupware · phpgroupware27 Ağu 2003

  • CVE-2004-0017
    30İzleyin

    Multiple SQL injection vulnerabilities in the (1) calendar and (2) infolog modules for phpgroupware 0.9.14 allow remote attackers to perform

    YüksekCVSS 7,5İstismar yokEPSS %1

    phpgroupware · phpgroupware3 Şub 2004

  • CVE-2005-3347
    28İzleyin

    Multiple directory traversal vulnerabilities in index.php in phpSysInfo 2.4 and earlier, as used in phpgroupware 0.9.16 and earlier, and egr

    OrtaCVSS 6,8İstismar yokEPSS %4

    phpgroupware · phpgroupware17 Kas 2005

  • CVE-2010-0403
    28İzleyin

    Directory traversal vulnerability in about.php in phpGroupWare (phpgw) before 0.9.16.016 allows remote attackers to include and execute arbi

    OrtaCVSS 6,8İstismar yokEPSS %2

    phpgroupware · phpgroupware19 May 2010

  • CVE-2004-0875
    27İzleyin

    Multiple cross-site scripting (XSS) vulnerabilities in Phpgroupware (aka webdistro) 0.9.16.002 and earlier allow remote attackers to insert

    OrtaCVSS 6,8İstismar yokEPSS %1

    phpgroupware · phpgroupware23 Ara 2004

  • CVE-2009-4414
    27İzleyin

    SQL injection vulnerability in phpgwapi /inc/class.auth_sql.inc.php in phpGroupWare 0.9.16.12, and possibly other versions before 0.9.16.014

    OrtaCVSS 6,8İstismar yokEPSS %1

    phpgroupware · phpgroupware24 Ara 2009

  • CVE-2006-4458
    26İzleyin

    Directory traversal vulnerability in calendar/inc/class.holidaycalc.inc.php in phpGroupWare 0.9.16.010 and earlier allows remote attackers t

    OrtaCVSS 6,4Kavram kanıtıEPSS %3

    phpgroupware · phpgroupware31 Ağu 2006

  • CVE-2004-1385
    22İzleyin

    phpGroupWare 0.9.16.003 and earlier allows remote attackers to gain sensitive information via (1) unexpected characters in the session ID su

    OrtaCVSS 5,0Kavram kanıtıEPSS %7

    phpgroupware · phpgroupware31 Ara 2004

  • CVE-2004-2575
    20İzleyin

    phpGroupWare 0.9.14.005 and earlier allow remote attackers to obtain sensitive information via a direct request to (1) hook_admin.inc.php, (

    OrtaCVSS 5,0İstismar yokEPSS %2

    phpgroupware · phpgroupware31 Ara 2004

  • CVE-2004-2576
    20İzleyin

    class.vfs_dav.inc.php in phpGroupWare 0.9.16.000 does not create .htaccess files to enable authorization checks for access to users' home-di

    OrtaCVSS 5,0İstismar yokEPSS %2

    phpgroupware · phpgroupware31 Ara 2004

  • CVE-2004-2578
    20İzleyin

    phpGroupWare before 0.9.16.002 transmits the (1) header admin and (2) setup passwords in plaintext via cookies, which allows remote attacker

    OrtaCVSS 5,0İstismar yokEPSS %1

    phpgroupware · phpgroupware31 Ara 2004

  • CVE-2004-2577
    20İzleyin

    The acl_check function in phpGroupWare 0.9.16RC2 always returns True, even when mkdir does not behave as expected, which could allow remote

    OrtaCVSS 5,0İstismar yokEPSS %1

    phpgroupware · phpgroupware31 Ara 2004

  • CVE-2004-1384
    18İzleyin

    Multiple cross-site scripting (XSS) vulnerabilities in phpGroupWare 0.9.16.003 and earlier allow remote attackers to inject arbitrary web sc

    OrtaCVSS 4,3Kavram kanıtıEPSS %4

    phpgroupware · phpgroupware31 Ara 2004

  • CVE-2004-2574
    18İzleyin

    Cross-site scripting (XSS) vulnerability in index.php in phpGroupWare 0.9.14.005 and earlier allows remote attackers to inject arbitrary web

    OrtaCVSS 4,3Kavram kanıtıEPSS %4

    phpgroupware · phpgroupware31 Ara 2004

  • CVE-2009-4416
    18İzleyin

    Cross-site scripting (XSS) vulnerability in login.php in phpGroupWare 0.9.16.12, and possibly other versions before 0.9.16.014, allows remot

    OrtaCVSS 4,3İstismar yokEPSS %2

    phpgroupware · phpgroupware24 Ara 2009