Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2009-4414
Description:SQL injection vulnerability in phpgwapi /inc/class.auth_sql.inc.php in phpGroupWare 0.9.16.12, and possibly other versions before 0.9.16.014, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the passwd parameter to login.php.
Test IDs: 1.3.6.1.4.1.25623.1.0.66772   1.3.6.1.4.1.25623.1.0.100237  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2009-4414
BugTraq ID: 35761
http://www.securityfocus.com/bid/35761
http://www.openwall.com/lists/oss-security/2009/12/20/1
http://www.osvdb.org/56178
http://secunia.com/advisories/35519
XForce ISS Database: phpgroupware-login-sql-injection(51922)
https://exchange.xforce.ibmcloud.com/vulnerabilities/51922




© 1998-2025 E-Soft Inc. All rights reserved.