Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2005-1202

Overview

Vulnerability Score 6.8 6.8
CVE Id CVE-2005-1202
Last Modified 05 Sep 2008 04:48:31
Published 02 May 2005 12:00:00
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact PARTIAL PARTIAL
Availability Impact PARTIAL PARTIAL
Access Vector NETWORK
Access Complexity MEDIUM
Authentication NONE

CVE-2005-1202

Summary

Multiple cross-site scripting (XSS) vulnerabilities in eGroupware before 1.0.0.007 allow remote attackers to inject arbitrary web script or HTML via the (1) ab_id, (2) page, (3) type, or (4) lang parameter to index.php or (5) category_id parameter.

Vulnerable Systems

Application

  • Egroupware 1.0

  • Egroupware 1.0.1

  • Egroupware 1.0.3

  • Egroupware 1.0.6


References

BID - 13212

CONFIRM - http://sourceforge.net/project/shownotes.php?release_id=320768

GENTOO - GLSA-200504-24

SECUNIA - 14982

OSVDB - 15751

MISC - http://www.gulftech.org/?node=research&article_id=00069-04202005

BUGTRAQ - 20050420 Multiple eGroupware Vulnerabilities


Last Updated: 27 May 2016 10:40:05