PT-2012-2015 · Egroupware · Egroupware Enterprise Line+1

Publicado

2012-08-31

·

Atualizado

2012-12-17

·

CVE-2011-4949

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions EGroupware Enterprise Line versions prior to 11.1.20110804-1 EGroupware Community Edition versions prior to 1.8.001.20110805
Description The issue allows remote attackers to execute arbitrary SQL commands. This is achieved via the id parameter in the phpgwapi/js/dhtmlxtree/samples/with db/loaddetails.php file.
Recommendations For EGroupware Enterprise Line versions prior to 11.1.20110804-1, update to version 11.1.20110804-1 or later. For EGroupware Community Edition versions prior to 1.8.001.20110805, update to version 1.8.001.20110805 or later.

Exploit

Correção

RCE

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2011-4949

Produtos afetados

Egroupware Community Edition
Egroupware Enterprise Line