Vulnerability Name: | CVE-2003-0504 (CCN-12497) | ||||||||
Assigned: | 2003-07-02 | ||||||||
Published: | 2003-07-02 | ||||||||
Updated: | 2016-10-18 | ||||||||
Summary: | Multiple cross-site scripting (XSS) vulnerabilities in Phpgroupware 0.9.14.003 (aka webdistro) allow remote attackers to insert arbitrary HTML or web script, as demonstrated with a request to index.php in the addressbook module. | ||||||||
CVSS v3 Severity: | 3.7 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: CCN Type: BugTraq Mailing List, Wed Jul 02 2003 - 11:37:37 CDT [KSA-003] Cross Site Scripting Vulnerability in Phpgroupware Source: MITRE Type: CNA CVE-2003-0504 Source: MITRE Type: CNA CVE-2003-0582 Source: CONECTIVA Type: UNKNOWN CLA-2003:697 Source: CCN Type: Conectiva Linux Security Announcement CLSA-2003:697 phpgroupware Source: BUGTRAQ Type: UNKNOWN 20030702 [KSA-003] Cross Site Scripting Vulnerability in Phpgroupware Source: DEBIAN Type: UNKNOWN DSA-365 Source: DEBIAN Type: DSA-365 phpgroupware -- several vulnerabilities Source: MANDRAKE Type: UNKNOWN MDKSA-2003:077 Source: CCN Type: OSVDB ID: 2243 phpGroupWare index.php Addressbook XSS Source: CCN Type: phpGroupWare Web site News Source: MISC Type: UNKNOWN http://www.security-corporation.com/articles-20030702-005.html Source: CCN Type: BID-8088 Multiple PHPGroupWare HTML Injection Vulnerabilities Source: CCN Type: BID-8265 PHPGroupWare Unspecified Remote File Include Vulnerability Source: XF Type: UNKNOWN phpgroupware-multiple-xss(12497) | ||||||||
Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |