Vulnerability Name: | CVE-2009-4416 (CCN-51923) | ||||||||||||||||
Assigned: | 2009-07-22 | ||||||||||||||||
Published: | 2009-07-22 | ||||||||||||||||
Updated: | 2017-08-17 | ||||||||||||||||
Summary: | Cross-site scripting (XSS) vulnerability in login.php in phpGroupWare 0.9.16.12, and possibly other versions before 0.9.16.014, allows remote attackers to inject arbitrary web script or HTML via an arbitrary parameter whose name begins with the "phpgw_" sequence. | ||||||||||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N) 3.9 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:TF/RC:C)
3.9 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:TF/RC:C)
| ||||||||||||||||
Vulnerability Type: | CWE-79 | ||||||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2009-4416 Source: MISC Type: Patch http://kambing.ui.ac.id/gentoo-portage/www-apps/phpgroupware/files/phpgroupware-SA35519.patch Source: CCN Type: SA35519 phpGroupWare Multiple Vulnerabilities Source: SECUNIA Type: Vendor Advisory 35519 Source: CONFIRM Type: UNKNOWN http://svn.savannah.gnu.org/viewvc/branches/Version-0_9_16-branch/login.php?r1=19063&r2=19117&pathrev=19117&sortby=date&root=phpgroupware Source: CONFIRM Type: UNKNOWN http://svn.savannah.gnu.org/viewvc/branches/Version-0_9_16-branch/phpgwapi/doc/CHANGELOG?r1=17045&r2=19117&pathrev=19117&sortby=date&root=phpgroupware Source: CCN Type: phpGroupWare SVN Repository start to prepare 0.9.16.014 release - fixes SA35519 Source: CONFIRM Type: UNKNOWN http://svn.savannah.gnu.org/viewvc?view=rev&root=phpgroupware&sortby=date&revision=19117 Source: DEBIAN Type: DSA-1978 phpgroupware -- several vulnerabilities Source: MLIST Type: UNKNOWN [oss-security] 20091220 CVE request: phpgroupware Source: OSVDB Type: UNKNOWN 56179 Source: CCN Type: OSVDB ID: 56179 phpGroupWare login.php phpgw_* Parameter XSS Source: CCN Type: phpGroupWare Web site phpGroupWare Source: BID Type: UNKNOWN 35761 Source: CCN Type: BID-35761 phpGroupWare Multiple Input Validation Vulnerabilities Source: XF Type: UNKNOWN phpgroupware-query-xss(51923) Source: XF Type: UNKNOWN phpgroupware-query-xss(51923) | ||||||||||||||||
Vulnerable Configuration: | Configuration 1:![]() | ||||||||||||||||
Oval Definitions | |||||||||||||||||
| |||||||||||||||||
BACK |