Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [day] [month] [year] [list]
Date: Wed, 12 Aug 2009 13:37:47 +0200
From: Alex Legler <a3li@...too.org>
To: oss-security@...ts.openwall.com
Subject: CVE request: phpgroupware

Hey,

can I please get a CVE/CVEs for these issues:

1) Local file disclosure via the "csvfile" parameter to
addressbook/csv_import.php

2) SQL injection via the "passwd" parameter to login.php -- requires
magic_quotes_gpc=off

3) XSS via parameters starting with "phpgw_" in login.php

4) Local file inclusion and execution via the "conv_type" parameter to
addressbook/inc/class.uiXport.inc.php

All addressed in
http://svn.savannah.gnu.org/viewvc?view=rev&root=phpgroupware&sortby=date&revision=19117

References:
http://secunia.com/advisories/35519
http://www.securityfocus.com/bid/35761
http://xforce.iss.net/xforce/xfdb/51922

Thanks,
Alex

Download attachment "signature.asc" of type "application/pgp-signature" (199 bytes)

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.