Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2009-4416

Опубликовано: 24 дек. 2009
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 4.3

Описание

Cross-site scripting (XSS) vulnerability in login.php in phpGroupWare 0.9.16.12, and possibly other versions before 0.9.16.014, allows remote attackers to inject arbitrary web script or HTML via an arbitrary parameter whose name begins with the "phpgw_" sequence.

РелизСтатусПримечание
dapper

ignored

end of life
devel

DNE

pulled 2010-07-27
hardy

ignored

end of life
intrepid

ignored

end of life, was needed
jaunty

released

1:0.9.16.012+dfsg-8+lenny1build0.9.04.1
karmic

released

1:0.9.16.012+dfsg-8+lenny1build0.9.10.1
lucid

not-affected

1:0.9.16.012+dfsg-10
maverick

DNE

pulled 2010-07-27
natty

DNE

pulled 2010-07-27
oneiric

DNE

pulled 2010-07-27

Показывать по

Ссылки на источники

EPSS

Процентиль: 67%
0.00557
Низкий

4.3 Medium

CVSS2

Связанные уязвимости

nvd
почти 16 лет назад

Cross-site scripting (XSS) vulnerability in login.php in phpGroupWare 0.9.16.12, and possibly other versions before 0.9.16.014, allows remote attackers to inject arbitrary web script or HTML via an arbitrary parameter whose name begins with the "phpgw_" sequence.

debian
почти 16 лет назад

Cross-site scripting (XSS) vulnerability in login.php in phpGroupWare ...

github
больше 3 лет назад

Cross-site scripting (XSS) vulnerability in login.php in phpGroupWare 0.9.16.12, and possibly other versions before 0.9.16.014, allows remote attackers to inject arbitrary web script or HTML via an arbitrary parameter whose name begins with the "phpgw_" sequence.

EPSS

Процентиль: 67%
0.00557
Низкий

4.3 Medium

CVSS2