![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
CVE ID: | CVE-2004-1467 |
Description: | Multiple cross-site scripting (XSS) vulnerabilities in eGroupWare 1.0.00.003 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) date or search text field in the calendar module, (2) Field parameter, Filter parameter, QField parameter, Start parameter or Search field in the address module, (3) Subject field in the message module or (4) Subject field in the Ticket module. |
Test IDs: | 1.3.6.1.4.1.25623.1.0.54663 1.3.6.1.4.1.25623.1.0.14358 |
Cross References: |
Common Vulnerability Exposure (CVE) ID: CVE-2004-1467 BugTraq ID: 11013 http://www.securityfocus.com/bid/11013 Bugtraq: 20040822 Multiple Cross Site Scripting Vulnerabilities in eGroupWare (Google Search) http://www.securityfocus.com/archive/1/372603 http://www.gentoo.org/security/en/glsa/glsa-200409-06.xml XForce ISS Database: egroupware-mult-modules-xss(17078) https://exchange.xforce.ibmcloud.com/vulnerabilities/17078 |