CVE-2007-3155
https://notcve.org/view.php?id=CVE-2007-3155
Unspecified vulnerability in eGroupWare before 1.2.107-2 has unknown impact and attack vectors related to ADOdb. NOTE: due to lack of details from the vendor, it is uncertain whether this issue is already covered by another CVE identifier. Vulnerabilidad no especificada en eGroupWare anterior a 1.2.107-2 tiene un impacto desconocido y vectores de ataque relacionados con ADOdb. NOTA: debido a la carencia de detalles del vendedor, es incierto si este asunto fue cubierto ya por otro identificador de CVE. • http://osvdb.org/37188 http://secunia.com/advisories/25454 http://sourceforge.net/project/shownotes.php?release_id=513311&group_id=78745 http://sourceforge.net/project/shownotes.php?release_id=513749&group_id=78745 http://www.securityfocus.com/bid/24378 https://exchange.xforce.ibmcloud.com/vulnerabilities/34914 •
CVE-2007-3154
https://notcve.org/view.php?id=CVE-2007-3154
Unspecified vulnerability in Walter Zorn wz_tooltip.js (aka wz_tooltips) before 4.01, as used by eGroupWare before 1.2.107-2 and other packages, has unknown impact and remote attack vectors. Vulnerabilidad no especificada en Walter Zorn wz_tooltip.js (también conocido como wz_tooltips) anterior a 4.01, tal y como se utiliza por eGroupWare anterior a 1.2.107-2 y otros paquetes, tiene un impacto desconocido y vectores de ataque remotos. • http://osvdb.org/37187 http://secunia.com/advisories/25454 http://sourceforge.net/project/shownotes.php?release_id=513311&group_id=78745 http://sourceforge.net/project/shownotes.php?release_id=513749&group_id=78745 http://www.securityfocus.com/bid/24378 http://www.walterzorn.com/tooltip/history.htm https://exchange.xforce.ibmcloud.com/vulnerabilities/34913 •
CVE-2005-1203 – eGroupWare 1.0 - 'index.php?cats_app' SQL Injection
https://notcve.org/view.php?id=CVE-2005-1203
Multiple SQL injection vulnerabilities in index.php in eGroupware before 1.0.0.007 allow remote attackers to execute arbitrary SQL commands via the (1) filter or (2) cats_app parameter. • https://www.exploit-db.com/exploits/25437 https://www.exploit-db.com/exploits/25436 http://marc.info/?l=bugtraq&m=111401760125555&w=2 http://secunia.com/advisories/14982 http://security.gentoo.org/glsa/glsa-200504-24.xml http://sourceforge.net/project/shownotes.php?release_id=320768 http://www.gulftech.org/?node=research&article_id=00069-04202005 http://www.osvdb.org/15753 http://www.securityfocus.com/bid/13212 •
CVE-2005-1202 – eGroupWare 1.0 - '/sitemgr-site/index.php?category_id' Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2005-1202
Multiple cross-site scripting (XSS) vulnerabilities in eGroupware before 1.0.0.007 allow remote attackers to inject arbitrary web script or HTML via the (1) ab_id, (2) page, (3) type, or (4) lang parameter to index.php or (5) category_id parameter. • https://www.exploit-db.com/exploits/25435 https://www.exploit-db.com/exploits/25434 http://marc.info/?l=bugtraq&m=111401760125555&w=2 http://secunia.com/advisories/14982 http://security.gentoo.org/glsa/glsa-200504-24.xml http://sourceforge.net/project/shownotes.php?release_id=320768 http://www.gulftech.org/?node=research&article_id=00069-04202005 http://www.osvdb.org/15751 http://www.securityfocus.com/bid/13212 •
CVE-2005-1129
https://notcve.org/view.php?id=CVE-2005-1129
eGroupWare 1.0.6 and earlier, when an e-mail is composed with an attachment but not sent, will send that attachment in the next e-mail, which may cause sensitive information to be sent to the wrong recipient. • http://archives.neohapsis.com/archives/bugtraq/2005-04/0157.html http://secunia.com/advisories/14940 http://www.osvdb.org/15499 http://www.securityfocus.com/bid/13137 https://exchange.xforce.ibmcloud.com/vulnerabilities/20088 •