PT-2004-1243 · Phpgroupware · Phpgroupware
Published
2004-01-14
·
Updated
2008-09-05
·
CVE-2004-0017
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
phpgroupware version 0.9.14
Description
The issue concerns SQL injection vulnerabilities in the calendar and infolog modules, allowing remote attackers to execute unauthorized database operations.
Recommendations
For phpgroupware version 0.9.14, consider disabling the calendar and infolog modules until a patch is available to prevent potential SQL injection attacks.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Phpgroupware