Phpgroupware

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 27
    Known Exploited: 0
    4
    Critical Level Threats
    8
    High Level Threats
    15
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2010-0403

    Directory traversal vulnerability in about.php in phpGroupWare (phpgw) before 0.9.16.016 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the app parameter.

    Last Modified: Apr 11, 2025
    Published: May 18, 2010

    CVE-2010-0404

    Multiple SQL injection vulnerabilities in phpGroupWare (phpgw) before 0.9.16.016 allow remote attackers to execute arbitrary SQL commands via unspecified parameters to (1) class.sessions_db.inc.php, (2) class.translation_sql.inc.php, or (3) class.auth_sql.inc.php in phpgwapi/inc/.

    Last Modified: Apr 11, 2025
    Published: May 18, 2010

    CVE-2009-4414

    SQL injection vulnerability in phpgwapi /inc/class.auth_sql.inc.php in phpGroupWare 0.9.16.12, and possibly other versions before 0.9.16.014, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the passwd parameter to login.php.

    Last Modified: Apr 23, 2026
    Published: Dec 24, 2009

    CVE-2009-4415

    Multiple directory traversal vulnerabilities in phpGroupWare 0.9.16.12, and possibly other versions before 0.9.16.014, allow remote attackers to (1) read arbitrary files via the csvfile parameter to addressbook/csv_import.php, or (2) include and execute arbitrary local files via the conv_type parameter in addressbook/inc/class.uiXport.inc.php.

    Last Modified: Apr 23, 2026
    Published: Dec 24, 2009

    CVE-2009-4416

    Cross-site scripting (XSS) vulnerability in login.php in phpGroupWare 0.9.16.12, and possibly other versions before 0.9.16.014, allows remote attackers to inject arbitrary web script or HTML via an arbitrary parameter whose name begins with the "phpgw_" sequence.

    Last Modified: Apr 23, 2026
    Published: Dec 24, 2009
    Items Per Page
    Phpgroupware Vulnerabilities & Security CVEs | CVE-DB