peter bassill · operator
$ cve CVE-2004-1384 JSON

CVE-2004-1384 EXPLOIT

4.3
MEDIUM · CVSS 2.0 · EPSS 4% (pctl 90)

Patch early

A public exploit exists.

Description

Multiple cross-site scripting (XSS) vulnerabilities in phpGroupWare 0.9.16.003 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) kp3, (2) type, (3) msg, (4) forum_id, (5) pos, (6) cats_app, (7) cat_id, (8) msgball[msgnum], (9) fldball[acctnum] parameters to index.php or (10) ticket_id to viewticket_details.php.

Scoring

CVSS4.3 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
EPSS4.04% — more likely to be exploited than 90% of all CVEs
On CISA KEVno
Public exploityes
Published2004-12-31
Last modified2026-06-16

Affected (1)

VendorProduct
phpgroupwarephpgroupware

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD