HIGH
Multiple SQL injection vulnerabilities in phpGroupWare (phpgw) before 0.9.16.016 allow remote attackers to execute arbitrary SQL commands via unspecified parameters to (1) class.sessions_db.inc.php, (2) class.translation_sql.inc.php, or (3) class.auth_sql.inc.php in phpgwapi/inc/
Published May 18, 2010
7.5
HIGHCVSS 2.0
EPSS 2.33%
Description
Multiple SQL injection vulnerabilities in phpGroupWare (phpgw) before 0.9.16.016 allow remote attackers to execute arbitrary SQL commands via unspecified parameters to (1) class.sessions_db.inc.php, (2) class.translation_sql.inc.php, or (3) class.auth_sql.inc.php in phpgwapi/inc/.
Affected products
No data.
OR
- ≤ 0.9.16.015
- 0.9.16
- 0.9.16.000
- 0.9.16.001
- 0.9.16.002
- 0.9.16.003
- 0.9.16.005
- 0.9.16.010
- 0.9.16.011
- 0.9.16.012
- 0.9.16.014
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (9)
- http://download.phpgroupware.org/ x_refsource_CONFIRMPatchVendor Advisory
- http://forums.phpgroupware.org/index.php?t=msg&th=98662&start=0&rid=0 x_refsource_CONFIRMPatch
- http://lists.gnu.org/archive/html/phpgroupware-users/2010-05/msg00004.html mailing-listx_refsource_MLISTPatch
- http://secunia.com/advisories/39665 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/39731 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://www.debian.org/security/2010/dsa-2046 vendor-advisoryx_refsource_DEBIAN
- http://www.securityfocus.com/archive/1/511299/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.vupen.com/english/advisories/2010/1145 vdb-entryx_refsource_VUPENVendor Advisory
- http://www.vupen.com/english/advisories/2010/1146 vdb-entryx_refsource_VUPENVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| http://download.phpgroupware.org/ | x_refsource_CONFIRMPatchVendor Advisory | |
| http://forums.phpgroupware.org/index.php?t=msg&th=98662&start=0&rid=0 | x_refsource_CONFIRMPatch | |
| http://lists.gnu.org/archive/html/phpgroupware-users/2010-05/msg00004.html | mailing-listx_refsource_MLISTPatch | |
| http://secunia.com/advisories/39665 | third-party-advisoryx_refsource_SECUNIAVendor Advisory | |
| http://secunia.com/advisories/39731 | third-party-advisoryx_refsource_SECUNIAVendor Advisory | |
| http://www.debian.org/security/2010/dsa-2046 | vendor-advisoryx_refsource_DEBIAN | |
| http://www.securityfocus.com/archive/1/511299/100/0/threaded | mailing-listx_refsource_BUGTRAQ | |
| http://www.vupen.com/english/advisories/2010/1145 | vdb-entryx_refsource_VUPENVendor Advisory | |
| http://www.vupen.com/english/advisories/2010/1146 | vdb-entryx_refsource_VUPENVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published May 18, 2010
Updated Aug 7, 2024
Reserved Jan 27, 2010
Link CVE-2010-0404
CISA Vulnrichment
Updated n/a