PT-2004-2300 · Phpgroupware · Phpgroupware

James Bercegay

·

Published

2004-12-31

·

Updated

2017-07-11

·

CVE-2004-1385

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions: phpGroupWare versions 0.9.16.003 and earlier
Description: The issue allows remote attackers to gain sensitive information. This can be achieved through unexpected characters in the session ID, such as shell metacharacters, an invalid appname parameter to "preferences.php", or an invalid menuaction parameter to "index.php", which reveals the web server path in an error message.
Recommendations: For phpGroupWare versions 0.9.16.003 and earlier, consider restricting access to the "preferences.php" and "index.php" scripts until a fix is available. As a temporary workaround, avoid using invalid parameters such as appname and menuaction in the affected API endpoints.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-1385

Affected Products

Phpgroupware