Page 4 of 21 results (0.002 seconds)

CVSS: 10.0EPSS: 0%CPEs: 1EXPL: 0

Unspecified vulnerability in Walter Zorn wz_tooltip.js (aka wz_tooltips) before 4.01, as used by eGroupWare before 1.2.107-2 and other packages, has unknown impact and remote attack vectors. Vulnerabilidad no especificada en Walter Zorn wz_tooltip.js (también conocido como wz_tooltips) anterior a 4.01, tal y como se utiliza por eGroupWare anterior a 1.2.107-2 y otros paquetes, tiene un impacto desconocido y vectores de ataque remotos. • http://osvdb.org/37187 http://secunia.com/advisories/25454 http://sourceforge.net/project/shownotes.php?release_id=513311&group_id=78745 http://sourceforge.net/project/shownotes.php?release_id=513749&group_id=78745 http://www.securityfocus.com/bid/24378 http://www.walterzorn.com/tooltip/history.htm https://exchange.xforce.ibmcloud.com/vulnerabilities/34913 •

CVSS: 10.0EPSS: 0%CPEs: 1EXPL: 0

Unspecified vulnerability in eGroupWare before 1.2.107-2 has unknown impact and attack vectors related to ADOdb. NOTE: due to lack of details from the vendor, it is uncertain whether this issue is already covered by another CVE identifier. Vulnerabilidad no especificada en eGroupWare anterior a 1.2.107-2 tiene un impacto desconocido y vectores de ataque relacionados con ADOdb. NOTA: debido a la carencia de detalles del vendedor, es incierto si este asunto fue cubierto ya por otro identificador de CVE. • http://osvdb.org/37188 http://secunia.com/advisories/25454 http://sourceforge.net/project/shownotes.php?release_id=513311&group_id=78745 http://sourceforge.net/project/shownotes.php?release_id=513749&group_id=78745 http://www.securityfocus.com/bid/24378 https://exchange.xforce.ibmcloud.com/vulnerabilities/34914 •

CVSS: 6.8EPSS: 2%CPEs: 4EXPL: 3

Multiple cross-site scripting (XSS) vulnerabilities in eGroupware before 1.0.0.007 allow remote attackers to inject arbitrary web script or HTML via the (1) ab_id, (2) page, (3) type, or (4) lang parameter to index.php or (5) category_id parameter. • https://www.exploit-db.com/exploits/25435 https://www.exploit-db.com/exploits/25434 http://marc.info/?l=bugtraq&m=111401760125555&w=2 http://secunia.com/advisories/14982 http://security.gentoo.org/glsa/glsa-200504-24.xml http://sourceforge.net/project/shownotes.php?release_id=320768 http://www.gulftech.org/?node=research&article_id=00069-04202005 http://www.osvdb.org/15751 http://www.securityfocus.com/bid/13212 •

CVSS: 7.5EPSS: 0%CPEs: 4EXPL: 4

Multiple SQL injection vulnerabilities in index.php in eGroupware before 1.0.0.007 allow remote attackers to execute arbitrary SQL commands via the (1) filter or (2) cats_app parameter. • https://www.exploit-db.com/exploits/25437 https://www.exploit-db.com/exploits/25436 http://marc.info/?l=bugtraq&m=111401760125555&w=2 http://secunia.com/advisories/14982 http://security.gentoo.org/glsa/glsa-200504-24.xml http://sourceforge.net/project/shownotes.php?release_id=320768 http://www.gulftech.org/?node=research&article_id=00069-04202005 http://www.osvdb.org/15753 http://www.securityfocus.com/bid/13212 •

CVSS: 2.1EPSS: 0%CPEs: 2EXPL: 0

eGroupWare 1.0.6 and earlier, when an e-mail is composed with an attachment but not sent, will send that attachment in the next e-mail, which may cause sensitive information to be sent to the wrong recipient. • http://archives.neohapsis.com/archives/bugtraq/2005-04/0157.html http://secunia.com/advisories/14940 http://www.osvdb.org/15499 http://www.securityfocus.com/bid/13137 https://exchange.xforce.ibmcloud.com/vulnerabilities/20088 •