5
CVE-2004-1385
- EPSS 4.59%
- Veröffentlicht 31.12.2004 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
phpGroupWare 0.9.16.003 and earlier allows remote attackers to gain sensitive information via (1) unexpected characters in the session ID such as shell metacharacters, (2) an invalid appname parameter to preferences.php or (3) an invalid menuaction parameter to index.php, which reveals the web server path in an error message.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Phpgroupware ≫ Phpgroupware Version0.9.12
Phpgroupware ≫ Phpgroupware Version0.9.13
Phpgroupware ≫ Phpgroupware Version0.9.14
Phpgroupware ≫ Phpgroupware Version0.9.14.003
Phpgroupware ≫ Phpgroupware Version0.9.14.005
Phpgroupware ≫ Phpgroupware Version0.9.14.006
Phpgroupware ≫ Phpgroupware Version0.9.14.007
Phpgroupware ≫ Phpgroupware Version0.9.16.000
Phpgroupware ≫ Phpgroupware Version0.9.16.002
Phpgroupware ≫ Phpgroupware Version0.9.16.003
Phpgroupware ≫ Phpgroupware Version0.9.16_rc1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 4.59% | 0.888 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|