CVE Vulnerabilities

CVE-2004-1385

Published: Dec 31, 2004 | Modified: Jul 11, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
UNTRIAGED

phpGroupWare 0.9.16.003 and earlier allows remote attackers to gain sensitive information via (1) unexpected characters in the session ID such as shell metacharacters, (2) an invalid appname parameter to preferences.php or (3) an invalid menuaction parameter to index.php, which reveals the web server path in an error message.

Affected Software

Name Vendor Start Version End Version
Phpgroupware Phpgroupware 0.9.12 (including) 0.9.12 (including)
Phpgroupware Phpgroupware 0.9.13 (including) 0.9.13 (including)
Phpgroupware Phpgroupware 0.9.14 (including) 0.9.14 (including)
Phpgroupware Phpgroupware 0.9.14.003 (including) 0.9.14.003 (including)
Phpgroupware Phpgroupware 0.9.14.005 (including) 0.9.14.005 (including)
Phpgroupware Phpgroupware 0.9.14.006 (including) 0.9.14.006 (including)
Phpgroupware Phpgroupware 0.9.14.007 (including) 0.9.14.007 (including)
Phpgroupware Phpgroupware 0.9.16.000 (including) 0.9.16.000 (including)
Phpgroupware Phpgroupware 0.9.16.002 (including) 0.9.16.002 (including)
Phpgroupware Phpgroupware 0.9.16.003 (including) 0.9.16.003 (including)
Phpgroupware Phpgroupware 0.9.16_rc1 (including) 0.9.16_rc1 (including)
Phpgroupware Ubuntu dapper *
Phpgroupware Ubuntu devel *
Phpgroupware Ubuntu edgy *
Phpgroupware Ubuntu feisty *

References