CVE-2004-1385 EXPLOIT
5.0
MEDIUM · CVSS 2.0 · EPSS 7.3% (pctl 94)
Patch early
A public exploit exists.
Description
phpGroupWare 0.9.16.003 and earlier allows remote attackers to gain sensitive information via (1) unexpected characters in the session ID such as shell metacharacters, (2) an invalid appname parameter to preferences.php or (3) an invalid menuaction parameter to index.php, which reveals the web server path in an error message.
Scoring
| CVSS | 5.0 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
| EPSS | 7.32% — more likely to be exploited than 94% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2004-12-31 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| phpgroupware | phpgroupware |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | phpGroupWare 0.9.x - 'index.php' Multiple SQL Injections | 2004-12-15 |
References
- http://marc.info/?l=bugtraq&m=110312656029072&w=2
- http://www.gentoo.org/security/en/glsa/glsa-200501-08.xml
- http://www.gulftech.org/?node=research&article_id=00054-12142004
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18497
- http://marc.info/?l=bugtraq&m=110312656029072&w=2
- http://www.gentoo.org/security/en/glsa/glsa-200501-08.xml
- http://www.gulftech.org/?node=research&article_id=00054-12142004
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18497
→ the Explorer · watch your stack · NVD