phpgroupware kayıtları
phpgroupware üreticisine ait 27 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 7
- Düzeltme kaydı olan
- %44,4
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Yıllara göre kayıt
Çubuk: toplam · koyu kısım: CISA KEV.
Tekrar eden sınıflar
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
27 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
41Planlayın | CVE-2001-0043İstismar yok | phpGroupWare before 0.9.7 allows remote attackers to execute arbitrary PHP commands by specifying a malicious include file in the phpgw_infophpgroupware · phpgroupware | Kritik10,0 | — | %3,1 | 16 Şub 2001 |
41Planlayın | CVE-2003-0599İstismar yok | Unknown vulnerability in the Virtual File System (VFS) capability for phpGroupWare 0.9.16preRC and versions before 0.9.14.004 with unknown iphpgroupware · phpgroupware | Kritik10,0 | — | %1,8 | 27 Ağu 2003 |
40Planlayın | CVE-2004-2407İstismar yok | Unknown vulnerability in phpGroupWare before 0.9.14.002 has unknown attack vectors and impact, related to a "security hole" in the Setup/Conphpgroupware · phpgroupware | Kritik10,0 | — | %1,5 | 31 Ara 2004 |
40Planlayın | CVE-2004-2406İstismar yok | Unknown "overflow" in the phpgw_config table for phpGroupWare before 0.9.14.002 has unknown attack vectors and impact.phpgroupware · phpgroupware | Kritik10,0 | — | %1,4 | 31 Ara 2004 |
31İzleyin | CVE-2009-4415İstismar yok | Multiple directory traversal vulnerabilities in phpGroupWare 0.9.16.12, and possibly other versions before 0.9.16.014, allow remote attackerphpgroupware · phpgroupware · CWE-22 | Yüksek7,5 | — | %3,4 | 24 Ara 2009 |
31İzleyin | CVE-2004-1383Kavram kanıtı | Multiple SQL injection vulnerabilities in phpGroupWare 0.9.16.003 and earlier allow remote attackers to execute arbitrary SQL statements viaphpgroupware · phpgroupware | Yüksek7,5 | — | %2,8 | 31 Ara 2004 |
31İzleyin | CVE-2004-2573Kavram kanıtı | PHP remote file inclusion vulnerability in tables_update.inc.php in phpGroupWare 0.9.14.005 and earlier allows remote attackers to execute aphpgroupware · phpgroupware | Yüksek7,5 | — | %2,6 | 31 Ara 2004 |
31İzleyin | CVE-2002-0536Kavram kanıtı | PHPGroupware 0.9.12 and earlier, when running with the magic_quotes_gpc feature disabled, allows remote attackers to compromise the databasephpgroupware · phpgroupware | Yüksek7,5 | — | %2,5 | 3 Tem 2002 |
31İzleyin | CVE-2010-0404İstismar yok | Multiple SQL injection vulnerabilities in phpGroupWare (phpgw) before 0.9.16.016 allow remote attackers to execute arbitrary SQL commands viphpgroupware · phpgroupware · CWE-89 | Yüksek7,5 | — | %2,3 | 19 May 2010 |
30İzleyin | CVE-2004-0016İstismar yok | The calendar module for phpgroupware 0.9.14 does not enforce the "save extension" feature for holiday files, which allows remote attackers tphpgroupware · phpgroupware | Yüksek7,5 | — | %1,6 | 3 Şub 2004 |
30İzleyin | CVE-2003-0657İstismar yok | Multiple SQL injection vulnerabilities in the infolog module for phpgroupware 0.9.14 and earlier could allow remote attackers to conduct unaphpgroupware · phpgroupware | Yüksek7,5 | — | %1,3 | 27 Ağu 2003 |
30İzleyin | CVE-2004-0017İstismar yok | Multiple SQL injection vulnerabilities in the (1) calendar and (2) infolog modules for phpgroupware 0.9.14 allow remote attackers to performphpgroupware · phpgroupware | Yüksek7,5 | — | %1,2 | 3 Şub 2004 |
28İzleyin | CVE-2005-3347İstismar yok | Multiple directory traversal vulnerabilities in index.php in phpSysInfo 2.4 and earlier, as used in phpgroupware 0.9.16 and earlier, and egrphpgroupware · phpgroupware · CWE-22 | Orta6,8 | — | %3,5 | 17 Kas 2005 |
28İzleyin | CVE-2010-0403İstismar yok | Directory traversal vulnerability in about.php in phpGroupWare (phpgw) before 0.9.16.016 allows remote attackers to include and execute arbiphpgroupware · phpgroupware · CWE-22 | Orta6,8 | — | %2,0 | 19 May 2010 |
27İzleyin | CVE-2004-0875İstismar yok | Multiple cross-site scripting (XSS) vulnerabilities in Phpgroupware (aka webdistro) 0.9.16.002 and earlier allow remote attackers to insert phpgroupware · phpgroupware | Orta6,8 | — | %1,3 | 23 Ara 2004 |
27İzleyin | CVE-2009-4414İstismar yok | SQL injection vulnerability in phpgwapi /inc/class.auth_sql.inc.php in phpGroupWare 0.9.16.12, and possibly other versions before 0.9.16.014phpgroupware · phpgroupware · CWE-89 | Orta6,8 | — | %1,3 | 24 Ara 2009 |
26İzleyin | CVE-2006-4458Kavram kanıtı | Directory traversal vulnerability in calendar/inc/class.holidaycalc.inc.php in phpGroupWare 0.9.16.010 and earlier allows remote attackers tphpgroupware · phpgroupware | Orta6,4 | — | %3,3 | 31 Ağu 2006 |
22İzleyin | CVE-2004-1385Kavram kanıtı | phpGroupWare 0.9.16.003 and earlier allows remote attackers to gain sensitive information via (1) unexpected characters in the session ID suphpgroupware · phpgroupware | Orta5,0 | — | %7,3 | 31 Ara 2004 |
20İzleyin | CVE-2004-2575İstismar yok | phpGroupWare 0.9.14.005 and earlier allow remote attackers to obtain sensitive information via a direct request to (1) hook_admin.inc.php, (phpgroupware · phpgroupware | Orta5,0 | — | %1,5 | 31 Ara 2004 |
20İzleyin | CVE-2004-2576İstismar yok | class.vfs_dav.inc.php in phpGroupWare 0.9.16.000 does not create .htaccess files to enable authorization checks for access to users' home-diphpgroupware · phpgroupware | Orta5,0 | — | %1,5 | 31 Ara 2004 |
20İzleyin | CVE-2004-2578İstismar yok | phpGroupWare before 0.9.16.002 transmits the (1) header admin and (2) setup passwords in plaintext via cookies, which allows remote attackerphpgroupware · phpgroupware | Orta5,0 | — | %1,4 | 31 Ara 2004 |
20İzleyin | CVE-2004-2577İstismar yok | The acl_check function in phpGroupWare 0.9.16RC2 always returns True, even when mkdir does not behave as expected, which could allow remote phpgroupware · phpgroupware | Orta5,0 | — | %1,4 | 31 Ara 2004 |
18İzleyin | CVE-2004-1384Kavram kanıtı | Multiple cross-site scripting (XSS) vulnerabilities in phpGroupWare 0.9.16.003 and earlier allow remote attackers to inject arbitrary web scphpgroupware · phpgroupware | Orta4,3 | — | %4,0 | 31 Ara 2004 |
18İzleyin | CVE-2004-2574Kavram kanıtı | Cross-site scripting (XSS) vulnerability in index.php in phpGroupWare 0.9.14.005 and earlier allows remote attackers to inject arbitrary webphpgroupware · phpgroupware | Orta4,3 | — | %3,6 | 31 Ara 2004 |
18İzleyin | CVE-2009-4416İstismar yok | Cross-site scripting (XSS) vulnerability in login.php in phpGroupWare 0.9.16.12, and possibly other versions before 0.9.16.014, allows remotphpgroupware · phpgroupware · CWE-79 | Orta4,3 | — | %2,3 | 24 Ara 2009 |
- CVE-2001-004341Planlayın
phpGroupWare before 0.9.7 allows remote attackers to execute arbitrary PHP commands by specifying a malicious include file in the phpgw_info
KritikCVSS 10,0İstismar yokEPSS %3phpgroupware · phpgroupware16 Şub 2001
- CVE-2003-059941Planlayın
Unknown vulnerability in the Virtual File System (VFS) capability for phpGroupWare 0.9.16preRC and versions before 0.9.14.004 with unknown i
KritikCVSS 10,0İstismar yokEPSS %2phpgroupware · phpgroupware27 Ağu 2003
- CVE-2004-240740Planlayın
Unknown vulnerability in phpGroupWare before 0.9.14.002 has unknown attack vectors and impact, related to a "security hole" in the Setup/Con
KritikCVSS 10,0İstismar yokEPSS %1phpgroupware · phpgroupware31 Ara 2004
- CVE-2004-240640Planlayın
Unknown "overflow" in the phpgw_config table for phpGroupWare before 0.9.14.002 has unknown attack vectors and impact.
KritikCVSS 10,0İstismar yokEPSS %1phpgroupware · phpgroupware31 Ara 2004
- CVE-2009-441531İzleyin
Multiple directory traversal vulnerabilities in phpGroupWare 0.9.16.12, and possibly other versions before 0.9.16.014, allow remote attacker
YüksekCVSS 7,5İstismar yokEPSS %3phpgroupware · phpgroupware24 Ara 2009
- CVE-2004-138331İzleyin
Multiple SQL injection vulnerabilities in phpGroupWare 0.9.16.003 and earlier allow remote attackers to execute arbitrary SQL statements via
YüksekCVSS 7,5Kavram kanıtıEPSS %3phpgroupware · phpgroupware31 Ara 2004
- CVE-2004-257331İzleyin
PHP remote file inclusion vulnerability in tables_update.inc.php in phpGroupWare 0.9.14.005 and earlier allows remote attackers to execute a
YüksekCVSS 7,5Kavram kanıtıEPSS %3phpgroupware · phpgroupware31 Ara 2004
- CVE-2002-053631İzleyin
PHPGroupware 0.9.12 and earlier, when running with the magic_quotes_gpc feature disabled, allows remote attackers to compromise the database
YüksekCVSS 7,5Kavram kanıtıEPSS %3phpgroupware · phpgroupware3 Tem 2002
- CVE-2010-040431İzleyin
Multiple SQL injection vulnerabilities in phpGroupWare (phpgw) before 0.9.16.016 allow remote attackers to execute arbitrary SQL commands vi
YüksekCVSS 7,5İstismar yokEPSS %2phpgroupware · phpgroupware19 May 2010
- CVE-2004-001630İzleyin
The calendar module for phpgroupware 0.9.14 does not enforce the "save extension" feature for holiday files, which allows remote attackers t
YüksekCVSS 7,5İstismar yokEPSS %2phpgroupware · phpgroupware3 Şub 2004
- CVE-2003-065730İzleyin
Multiple SQL injection vulnerabilities in the infolog module for phpgroupware 0.9.14 and earlier could allow remote attackers to conduct una
YüksekCVSS 7,5İstismar yokEPSS %1phpgroupware · phpgroupware27 Ağu 2003
- CVE-2004-001730İzleyin
Multiple SQL injection vulnerabilities in the (1) calendar and (2) infolog modules for phpgroupware 0.9.14 allow remote attackers to perform
YüksekCVSS 7,5İstismar yokEPSS %1phpgroupware · phpgroupware3 Şub 2004
- CVE-2005-334728İzleyin
Multiple directory traversal vulnerabilities in index.php in phpSysInfo 2.4 and earlier, as used in phpgroupware 0.9.16 and earlier, and egr
OrtaCVSS 6,8İstismar yokEPSS %4phpgroupware · phpgroupware17 Kas 2005
- CVE-2010-040328İzleyin
Directory traversal vulnerability in about.php in phpGroupWare (phpgw) before 0.9.16.016 allows remote attackers to include and execute arbi
OrtaCVSS 6,8İstismar yokEPSS %2phpgroupware · phpgroupware19 May 2010
- CVE-2004-087527İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in Phpgroupware (aka webdistro) 0.9.16.002 and earlier allow remote attackers to insert
OrtaCVSS 6,8İstismar yokEPSS %1phpgroupware · phpgroupware23 Ara 2004
- CVE-2009-441427İzleyin
SQL injection vulnerability in phpgwapi /inc/class.auth_sql.inc.php in phpGroupWare 0.9.16.12, and possibly other versions before 0.9.16.014
OrtaCVSS 6,8İstismar yokEPSS %1phpgroupware · phpgroupware24 Ara 2009
- CVE-2006-445826İzleyin
Directory traversal vulnerability in calendar/inc/class.holidaycalc.inc.php in phpGroupWare 0.9.16.010 and earlier allows remote attackers t
OrtaCVSS 6,4Kavram kanıtıEPSS %3phpgroupware · phpgroupware31 Ağu 2006
- CVE-2004-138522İzleyin
phpGroupWare 0.9.16.003 and earlier allows remote attackers to gain sensitive information via (1) unexpected characters in the session ID su
OrtaCVSS 5,0Kavram kanıtıEPSS %7phpgroupware · phpgroupware31 Ara 2004
- CVE-2004-257520İzleyin
phpGroupWare 0.9.14.005 and earlier allow remote attackers to obtain sensitive information via a direct request to (1) hook_admin.inc.php, (
OrtaCVSS 5,0İstismar yokEPSS %2phpgroupware · phpgroupware31 Ara 2004
- CVE-2004-257620İzleyin
class.vfs_dav.inc.php in phpGroupWare 0.9.16.000 does not create .htaccess files to enable authorization checks for access to users' home-di
OrtaCVSS 5,0İstismar yokEPSS %2phpgroupware · phpgroupware31 Ara 2004
- CVE-2004-257820İzleyin
phpGroupWare before 0.9.16.002 transmits the (1) header admin and (2) setup passwords in plaintext via cookies, which allows remote attacker
OrtaCVSS 5,0İstismar yokEPSS %1phpgroupware · phpgroupware31 Ara 2004
- CVE-2004-257720İzleyin
The acl_check function in phpGroupWare 0.9.16RC2 always returns True, even when mkdir does not behave as expected, which could allow remote
OrtaCVSS 5,0İstismar yokEPSS %1phpgroupware · phpgroupware31 Ara 2004
- CVE-2004-138418İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in phpGroupWare 0.9.16.003 and earlier allow remote attackers to inject arbitrary web sc
OrtaCVSS 4,3Kavram kanıtıEPSS %4phpgroupware · phpgroupware31 Ara 2004
- CVE-2004-257418İzleyin
Cross-site scripting (XSS) vulnerability in index.php in phpGroupWare 0.9.14.005 and earlier allows remote attackers to inject arbitrary web
OrtaCVSS 4,3Kavram kanıtıEPSS %4phpgroupware · phpgroupware31 Ara 2004
- CVE-2009-441618İzleyin
Cross-site scripting (XSS) vulnerability in login.php in phpGroupWare 0.9.16.12, and possibly other versions before 0.9.16.014, allows remot
OrtaCVSS 4,3İstismar yokEPSS %2phpgroupware · phpgroupware24 Ara 2009