vendor:
by:
Nahuel GrisolÃa
7.5
CVSS
HIGH
Remote Command Execution
CWE
Product Name:
Affected Version From: Confirmed in EGroupware 1.4.001+.002 and 1.6.001+.002. EGroupware Premium Line 9.1 and 9.2 is also affected. Other versions may also be affected.
Affected Version To:
Patch Exists: YES
Related CWE:
CPE: EGroupware
Platforms Tested: Multiple
2010
Remote Command Execution in EGroupware
EGroupware is prone to a remote command execution vulnerability because the software fails to adequately sanitize user-supplied input. Successful attacks can compromise the affected software and possibly the computer running EGroupware.
Mitigation:
Fixed in EGroupware version 1.6.003, EPL-9.1.20100309 and EPL-9.2.20100309