PT-2004-2300 · Phpgroupware · Phpgroupware
James Bercegay
·
Publicado
2004-12-31
·
Atualizado
2017-07-11
·
CVE-2004-1385
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
phpGroupWare versions 0.9.16.003 and earlier
Description:
The issue allows remote attackers to gain sensitive information. This can be achieved through unexpected characters in the session ID, such as shell metacharacters, an invalid
appname parameter to "preferences.php", or an invalid menuaction parameter to "index.php", which reveals the web server path in an error message.Recommendations:
For phpGroupWare versions 0.9.16.003 and earlier, consider restricting access to the "preferences.php" and "index.php" scripts until a fix is available. As a temporary workaround, avoid using invalid parameters such as
appname and menuaction in the affected API endpoints.Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Phpgroupware