PT-2005-4153 · Phpgroupware+2 · Phpgroupware+2

Christopher Kunz

·

Publicado

2005-11-18

·

Atualizado

2017-07-11

·

CVE-2005-3348

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions phpSysInfo versions 2.4 and earlier phpgroupware versions 0.9.16 and earlier egroupware versions prior to 1.0.0.009
Description The issue allows remote attackers to spoof web content and poison web caches. This is achieved via CRLF sequences in the charset parameter.
Recommendations For phpSysInfo versions 2.4 and earlier, update to a version later than 2.4 to resolve the issue. For phpgroupware versions 0.9.16 and earlier, update to a version later than 0.9.16 to resolve the issue. For egroupware versions prior to 1.0.0.009, update to version 1.0.0.009 or later to resolve the issue. As a temporary workaround, consider restricting access to the charset parameter in the affected API endpoint until a patch is available.

Correção

CSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2005-3348
DSA-897-1
DSA-898-1
DSA-899-1

Produtos afetados

Egroupware
Phpsysinfo
Phpgroupware