|
Message-ID: <20090812133747.625a78f1@neon>
Date: Wed, 12 Aug 2009 13:37:47 +0200
From: Alex Legler <a3li@...too.org>
To: oss-security@...ts.openwall.com
Subject: CVE request: phpgroupware
Hey,
can I please get a CVE/CVEs for these issues:
1) Local file disclosure via the "csvfile" parameter to
addressbook/csv_import.php
2) SQL injection via the "passwd" parameter to login.php -- requires
magic_quotes_gpc=off
3) XSS via parameters starting with "phpgw_" in login.php
4) Local file inclusion and execution via the "conv_type" parameter to
addressbook/inc/class.uiXport.inc.php
All addressed in
http://svn.savannah.gnu.org/viewvc?view=rev&root=phpgroupware&sortby=date&revision=19117
References:
http://secunia.com/advisories/35519
http://www.securityfocus.com/bid/35761
http://xforce.iss.net/xforce/xfdb/51922
Thanks,
Alex
Download attachment "signature.asc" of type "application/pgp-signature" (199 bytes)
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.