Vulnerabilities > CVE-2004-2578 - Unspecified vulnerability in PHPgroupware
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN phpgroupware
nessus
Summary
phpGroupWare before 0.9.16.002 transmits the (1) header admin and (2) setup passwords in plaintext via cookies, which allows remote attackers to sniff passwords.
Vulnerable Configurations
Nessus
NASL family | CGI abuses |
NASL id | PHPGROUPWARE_PLAINTEXT_COOKIE_AUTH_VULN.NASL |
description | The version of PhpGroupWare installed on the remote host is reported to be affected by a plaintext cookie authentication credentials information disclosure vulnerability. If web administration of PhpGroupWare is not conducted over an encrypted link, an attacker with the ability to sniff network traffic could easily retrieve these passwords. This may aid the attacker in further system compromise. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 14293 |
published | 2004-08-17 |
reporter | This script is Copyright (C) 2004-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/14293 |
title | phpGroupWare Admin/Setup Password Plaintext Cookie Storage |
code |
|
References
- http://web.archive.org/web/20040920024328/http://www.phpgroupware.org/
- http://web.archive.org/web/20040920024328/http://www.phpgroupware.org/
- http://www.osvdb.org/8354
- http://www.osvdb.org/8354
- http://www.securityfocus.com/bid/10895
- http://www.securityfocus.com/bid/10895
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16970
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16970