Openwall GNU/*/Linux - a small security-enhanced Linux distro for servers
[<prev] [next>] [day] [month] [year] [list]
Date: Wed, 12 Aug 2009 13:37:47 +0200
From: Alex Legler <a3li@...too.org>
To: oss-security@...ts.openwall.com
Subject: CVE request: phpgroupware

Hey,

can I please get a CVE/CVEs for these issues:

1) Local file disclosure via the "csvfile" parameter to
addressbook/csv_import.php

2) SQL injection via the "passwd" parameter to login.php -- requires
magic_quotes_gpc=off

3) XSS via parameters starting with "phpgw_" in login.php

4) Local file inclusion and execution via the "conv_type" parameter to
addressbook/inc/class.uiXport.inc.php

All addressed in
http://svn.savannah.gnu.org/viewvc?view=rev&root=phpgroupware&sortby=date&revision=19117

References:
http://secunia.com/advisories/35519
http://www.securityfocus.com/bid/35761
http://xforce.iss.net/xforce/xfdb/51922

Thanks,
Alex

[ CONTENT OF TYPE application/pgp-signature SKIPPED ]

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Powered by Openwall GNU/*/Linux - Powered by OpenVZ