Information Disclosure Vulnerability in phpGroupWare 0.9.16.003 and Earlier

Information Disclosure Vulnerability in phpGroupWare 0.9.16.003 and Earlier

CVE-2004-1385 · MEDIUM Severity

AV:N/AC:L/AU:N/C:P/I:N/A:N

phpGroupWare 0.9.16.003 and earlier allows remote attackers to gain sensitive information via (1) unexpected characters in the session ID such as shell metacharacters, (2) an invalid appname parameter to preferences.php or (3) an invalid menuaction parameter to index.php, which reveals the web server path in an error message.

Learn more about our Web App Pen Testing.