Vulnerabilities > CVE-2004-0875 - Unspecified vulnerability in PHPgroupware

047910
CVSS 6.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
phpgroupware
nessus

Summary

Multiple cross-site scripting (XSS) vulnerabilities in Phpgroupware (aka webdistro) 0.9.16.002 and earlier allow remote attackers to insert arbitrary HTML or web script, as demonstrated with a request to the wiki module.

Nessus

  • NASL familyCGI abuses : XSS
    NASL idPHPGROUPWARE_XSS.NASL
    descriptionThe remote host seems to be running PhpGroupWare, a multi-user groupware suite written in PHP. This issue exists due to a lack of sanitization of user-supplied data. A malicious attacker can exploit a flaw to conduct cross-site scripting attacks.
    last seen2020-06-01
    modified2020-06-02
    plugin id14708
    published2004-09-13
    reporterThis script is Copyright (C) 2004-2018 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/14708
    titlephpGroupWare Wiki Module XSS
  • NASL familyGentoo Local Security Checks
    NASL idGENTOO_GLSA-200409-22.NASL
    descriptionThe remote host is affected by the vulnerability described in GLSA-200409-22 (phpGroupWare: XSS vulnerability in wiki module) Due to an input validation error, the wiki module in the phpGroupWare suite is vulnerable to cross site scripting attacks. Impact : This vulnerability gives an attacker the ability to inject and execute malicious script code, potentially compromising the victim
    last seen2020-06-01
    modified2020-06-02
    plugin id14767
    published2004-09-17
    reporterThis script is Copyright (C) 2004-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/14767
    titleGLSA-200409-22 : phpGroupWare: XSS vulnerability in wiki module