CVE Vulnerabilities

CVE-2004-1385

Published: Dec 31, 2004 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

phpGroupWare 0.9.16.003 and earlier allows remote attackers to gain sensitive information via (1) unexpected characters in the session ID such as shell metacharacters, (2) an invalid appname parameter to preferences.php or (3) an invalid menuaction parameter to index.php, which reveals the web server path in an error message.

Affected Software

NameVendorStart VersionEnd Version
PhpgroupwarePhpgroupware0.9.12 (including)0.9.12 (including)
PhpgroupwarePhpgroupware0.9.13 (including)0.9.13 (including)
PhpgroupwarePhpgroupware0.9.14 (including)0.9.14 (including)
PhpgroupwarePhpgroupware0.9.14.003 (including)0.9.14.003 (including)
PhpgroupwarePhpgroupware0.9.14.005 (including)0.9.14.005 (including)
PhpgroupwarePhpgroupware0.9.14.006 (including)0.9.14.006 (including)
PhpgroupwarePhpgroupware0.9.14.007 (including)0.9.14.007 (including)
PhpgroupwarePhpgroupware0.9.16.000 (including)0.9.16.000 (including)
PhpgroupwarePhpgroupware0.9.16.002 (including)0.9.16.002 (including)
PhpgroupwarePhpgroupware0.9.16.003 (including)0.9.16.003 (including)
PhpgroupwarePhpgroupware0.9.16_rc1 (including)0.9.16_rc1 (including)
PhpgroupwareUbuntudapper*
PhpgroupwareUbuntudevel*
PhpgroupwareUbuntuedgy*
PhpgroupwareUbuntufeisty*

References