Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.14293
Category:Web application abuses
Title:PhpGroupWare plaintext cookie authentication credentials vulnerability
Summary:The remote host seems to be running PhpGroupWare.;; PhpGroupWare is a multi-user groupware suite written in PHP.
Description:Summary:
The remote host seems to be running PhpGroupWare.

PhpGroupWare is a multi-user groupware suite written in PHP.

Vulnerability Insight:
This version is reported to contain a plaintext cookie authentication
credentials information disclosure vulnerability. If the web
administration of PHPGroupWare is not conducted over an encrypted link,
an attacker with the ability to sniff network traffic could easily
retrieve these passwords. This may aid the attacker in further system
compromise.

Solution:
Update to version 0.9.16.002 or newer

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:N/A:N

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2004-2578
BugTraq ID: 10895
http://www.securityfocus.com/bid/10895
http://www.osvdb.org/8354
XForce ISS Database: phpgroupware-plaintext-password(16970)
https://exchange.xforce.ibmcloud.com/vulnerabilities/16970
CopyrightCopyright (C) 2004 David Maciejak

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.