PT-2004-1243 · Phpgroupware · Phpgroupware

Published

2004-01-14

·

Updated

2008-09-05

·

CVE-2004-0017

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions phpgroupware version 0.9.14
Description The issue concerns SQL injection vulnerabilities in the calendar and infolog modules, allowing remote attackers to execute unauthorized database operations.
Recommendations For phpgroupware version 0.9.14, consider disabling the calendar and infolog modules until a patch is available to prevent potential SQL injection attacks.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-0017
DSA-419

Affected Products

Phpgroupware