PT-2004-3468 · Phpgroupware · Phpgroupware

Caeies

·

Published

2004-12-31

·

Updated

2008-09-05

·

CVE-2004-2577

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions phpGroupWare version 0.9.16RC2
Description The issue is related to the acl check function, which always returns True, even when mkdir does not behave as expected. This could allow remote attackers to obtain sensitive information via WebDAV from users' home directories that lack .htaccess files. The exact impacts of this issue are not fully understood and may extend beyond the described scenario.
Recommendations For phpGroupWare version 0.9.16RC2, as a temporary workaround, consider disabling the acl check function until a patch is available. Restrict access to sensitive information in users' home directories to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-2577

Affected Products

Phpgroupware