vendor:
eGroupWare
by:
SecurityFocus
7.5
CVSS
HIGH
Cross-site Scripting and SQL Injection
89, 89
CWE
Product Name: eGroupWare
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2005
eGroupWare Multiple Input Validation Vulnerabilities
eGroupWare is prone to multiple input validation vulnerabilities due to a failure of the application to properly validate user-supplied input. These issues result in cross-site scripting and SQL injection attacks. An example of a vulnerable URL is http://egroupware/index.php?menuaction=preferences.uicategories.index&cats_app=foobar[SQL].
Mitigation:
Upgrade to the latest version of eGroupWare.