|
|
| |
|
| |
eGroupWare: XSS and SQL injection vulnerabilities
| Package(s): | eGroupWare |
CVE #(s): | |
| Created: | April 25, 2005 |
Updated: | April 27, 2005 |
| Description: |
Multiple SQL injection and cross-site scripting vulnerabilities have been
found in several eGroupWare modules. An attacker could possibly use the
SQL injection vulnerabilities to gain information from the database.
Furthermore the cross-site scripting issues give an attacker the ability to
inject and execute malicious script code or to steal cookie based
authentication credentials, potentially compromising the victim's browser. |
| Alerts: |
|
( Log in to post comments)
|
|
|