CVE-2014-2987
- EPSS 1.36%
- Veröffentlicht 26.10.2014 18:55:04
- Zuletzt bearbeitet 06.05.2026 22:30:45
Multiple cross-site request forgery (CSRF) vulnerabilities in EGroupware Enterprise Line (EPL) before 1.1.20140505, EGroupware Community Edition before 1.8.007.20140506, and EGroupware before 14.1 beta allow remote attackers to hijack the authenticat...
CVE-2012-2211
- EPSS 1.23%
- Veröffentlicht 22.11.2012 12:28:40
- Zuletzt bearbeitet 16.06.2026 23:41:11
Cross-site scripting (XSS) vulnerability in phpgwapi/inc/common_functions_inc.php in eGroupware before 1.8.004.20120405 allows remote attackers to inject arbitrary web script or HTML via the menuaction parameter to etemplate/process_exec.php. NOTE: ...
CVE-2011-4951
- EPSS 1.49%
- Veröffentlicht 31.08.2012 22:55:01
- Zuletzt bearbeitet 16.06.2026 23:35:42
Open redirect vulnerability in phpgwapi/ntlm/index.php in EGroupware Enterprise Line (EPL) before 11.1.20110804-1 and EGroupware Community Edition before 1.8.001.20110805 allows remote attackers to redirect users to arbitrary web sites and conduct ph...
CVE-2011-4950
- EPSS 1.41%
- Veröffentlicht 31.08.2012 22:55:01
- Zuletzt bearbeitet 16.06.2026 23:35:42
Cross-site scripting (XSS) vulnerability in phpgwapi/js/jscalendar/test.php in EGroupware Enterprise Line (EPL) before 11.1.20110804-1 and EGroupware Community Edition before 1.8.001.20110805 allows remote attackers to inject arbitrary web script or ...
CVE-2011-4949
- EPSS 1.52%
- Veröffentlicht 31.08.2012 22:55:01
- Zuletzt bearbeitet 16.06.2026 23:35:42
SQL injection vulnerability in phpgwapi/js/dhtmlxtree/samples/with_db/loaddetails.php in EGroupware Enterprise Line (EPL) before 11.1.20110804-1 and EGroupware Community Edition before 1.8.001.20110805 allows remote attackers to execute arbitrary SQL...
- EPSS 2.26%
- Veröffentlicht 31.08.2012 22:55:01
- Zuletzt bearbeitet 16.06.2026 23:35:41
Directory traversal vulnerability in admin/remote.php in EGroupware Enterprise Line (EPL) before 11.1.20110804-1 and EGroupware Community Edition before 1.8.001.20110805 allows remote attackers to read arbitrary files via a ..%2f (encoded dot dot sla...
CVE-2010-3314
- EPSS 3.33%
- Veröffentlicht 22.09.2010 19:00:03
- Zuletzt bearbeitet 16.06.2026 23:22:34
Cross-site scripting (XSS) vulnerability in login.php in EGroupware 1.4.001+.002; 1.6.001+.002 and possibly other versions before 1.6.003; and EPL 9.1 before 9.1.20100309 and 9.2 before 9.2.20100309; allows remote attackers to inject arbitrary web sc...
CVE-2010-3313
- EPSS 8.5%
- Veröffentlicht 22.09.2010 19:00:03
- Zuletzt bearbeitet 16.06.2026 23:22:33
phpgwapi/js/fckeditor/editor/dialog/fck_spellerpages/spellerpages/serverscripts/spellchecker.php in EGroupware 1.4.001+.002; 1.6.001+.002 and possibly other versions before 1.6.003; and EPL 9.1 before 9.1.20100309 and 9.2 before 9.2.20100309; allows ...
- EPSS 1.63%
- Veröffentlicht 30.04.2008 16:17:00
- Zuletzt bearbeitet 16.06.2026 22:52:59
Multiple unspecified vulnerabilities in eGroupWare before 1.4.004 have unspecified attack vectors and "grave" impact when the web server has write access to a directory under the web document root.
CVE-2008-1502
- EPSS 10.5%
- Veröffentlicht 25.03.2008 19:44:00
- Zuletzt bearbeitet 16.06.2026 22:51:52
The _bad_protocol_once function in phpgwapi/inc/class.kses.inc.php in KSES, as used in eGroupWare before 1.4.003, Moodle before 1.8.5, and other products, allows remote attackers to bypass HTML filtering and conduct cross-site scripting (XSS) attacks...