PT-2004-2300 · Phpgroupware · Phpgroupware
James Bercegay
·
Published
2004-12-31
·
Updated
2017-07-11
·
CVE-2004-1385
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
phpGroupWare versions 0.9.16.003 and earlier
Description:
The issue allows remote attackers to gain sensitive information. This can be achieved through unexpected characters in the session ID, such as shell metacharacters, an invalid
appname parameter to "preferences.php", or an invalid menuaction parameter to "index.php", which reveals the web server path in an error message.Recommendations:
For phpGroupWare versions 0.9.16.003 and earlier, consider restricting access to the "preferences.php" and "index.php" scripts until a fix is available. As a temporary workaround, avoid using invalid parameters such as
appname and menuaction in the affected API endpoints.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Phpgroupware