header-logo
Suggest Exploit
vendor:
eGroupWare
by:
SecurityFocus
7.5
CVSS
HIGH
Cross-site Scripting and SQL Injection
89, 89
CWE
Product Name: eGroupWare
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2005

eGroupWare Multiple Input Validation Vulnerabilities

eGroupWare is prone to multiple input validation vulnerabilities due to a failure of the application to properly validate user-supplied input. These issues result in cross-site scripting and SQL injection attacks. An example of a vulnerable URL is http://egroupware/index.php?menuaction=preferences.uicategories.index&cats_app=foobar[SQL].

Mitigation:

Upgrade to the latest version of eGroupWare.
Source

Exploit-DB raw data:

source: https://www.securityfocus.com/bid/13212/info
   
eGroupWare is prone to multiple input validation vulnerabilities. A fixed version is available.
   
The issues arise due to a failure of the application to properly validate user-supplied input. These issues result in cross-site scripting and SQL injection attacks. 

http://egroupware/index.php?menuaction=preferences.uicategories.index&cats_app=foobar[SQL]