Egroupware

Egroupware

26 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 1.36%
  • Veröffentlicht 26.10.2014 18:55:04
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Multiple cross-site request forgery (CSRF) vulnerabilities in EGroupware Enterprise Line (EPL) before 1.1.20140505, EGroupware Community Edition before 1.8.007.20140506, and EGroupware before 14.1 beta allow remote attackers to hijack the authenticat...

Exploit
  • EPSS 1.23%
  • Veröffentlicht 22.11.2012 12:28:40
  • Zuletzt bearbeitet 16.06.2026 23:41:11

Cross-site scripting (XSS) vulnerability in phpgwapi/inc/common_functions_inc.php in eGroupware before 1.8.004.20120405 allows remote attackers to inject arbitrary web script or HTML via the menuaction parameter to etemplate/process_exec.php. NOTE: ...

Exploit
  • EPSS 1.49%
  • Veröffentlicht 31.08.2012 22:55:01
  • Zuletzt bearbeitet 16.06.2026 23:35:42

Open redirect vulnerability in phpgwapi/ntlm/index.php in EGroupware Enterprise Line (EPL) before 11.1.20110804-1 and EGroupware Community Edition before 1.8.001.20110805 allows remote attackers to redirect users to arbitrary web sites and conduct ph...

Exploit
  • EPSS 1.41%
  • Veröffentlicht 31.08.2012 22:55:01
  • Zuletzt bearbeitet 16.06.2026 23:35:42

Cross-site scripting (XSS) vulnerability in phpgwapi/js/jscalendar/test.php in EGroupware Enterprise Line (EPL) before 11.1.20110804-1 and EGroupware Community Edition before 1.8.001.20110805 allows remote attackers to inject arbitrary web script or ...

Exploit
  • EPSS 1.52%
  • Veröffentlicht 31.08.2012 22:55:01
  • Zuletzt bearbeitet 16.06.2026 23:35:42

SQL injection vulnerability in phpgwapi/js/dhtmlxtree/samples/with_db/loaddetails.php in EGroupware Enterprise Line (EPL) before 11.1.20110804-1 and EGroupware Community Edition before 1.8.001.20110805 allows remote attackers to execute arbitrary SQL...

Exploit
  • EPSS 2.26%
  • Veröffentlicht 31.08.2012 22:55:01
  • Zuletzt bearbeitet 16.06.2026 23:35:41

Directory traversal vulnerability in admin/remote.php in EGroupware Enterprise Line (EPL) before 11.1.20110804-1 and EGroupware Community Edition before 1.8.001.20110805 allows remote attackers to read arbitrary files via a ..%2f (encoded dot dot sla...

Exploit
  • EPSS 3.33%
  • Veröffentlicht 22.09.2010 19:00:03
  • Zuletzt bearbeitet 16.06.2026 23:22:34

Cross-site scripting (XSS) vulnerability in login.php in EGroupware 1.4.001+.002; 1.6.001+.002 and possibly other versions before 1.6.003; and EPL 9.1 before 9.1.20100309 and 9.2 before 9.2.20100309; allows remote attackers to inject arbitrary web sc...

  • EPSS 8.5%
  • Veröffentlicht 22.09.2010 19:00:03
  • Zuletzt bearbeitet 16.06.2026 23:22:33

phpgwapi/js/fckeditor/editor/dialog/fck_spellerpages/spellerpages/serverscripts/spellchecker.php in EGroupware 1.4.001+.002; 1.6.001+.002 and possibly other versions before 1.6.003; and EPL 9.1 before 9.1.20100309 and 9.2 before 9.2.20100309; allows ...

  • EPSS 1.63%
  • Veröffentlicht 30.04.2008 16:17:00
  • Zuletzt bearbeitet 16.06.2026 22:52:59

Multiple unspecified vulnerabilities in eGroupWare before 1.4.004 have unspecified attack vectors and "grave" impact when the web server has write access to a directory under the web document root.

Exploit
  • EPSS 10.5%
  • Veröffentlicht 25.03.2008 19:44:00
  • Zuletzt bearbeitet 16.06.2026 22:51:52

The _bad_protocol_once function in phpgwapi/inc/class.kses.inc.php in KSES, as used in eGroupWare before 1.4.003, Moodle before 1.8.5, and other products, allows remote attackers to bypass HTML filtering and conduct cross-site scripting (XSS) attacks...