|
Family: CGI abuses --> Category: attack
PhpGroupWare multiple HTML injection vulnerabilities Vulnerability Scan
Vulnerability Scan Summary Checks for PhpGroupWare version
Detailed Explanation for this Vulnerability Test
The remote host seems to be running PhpGroupWare, is a multi-user groupware
suite written in PHP.
This version has been reported prone to multiple HTML injection vulnerabilities.
The issues present themselves due to a lack of sufficient input validation
performed on form fields used by PHPGroupWare modules.
A malicious attacker may inject arbitrary HTML and script code using these
form fields that may be incorporated into dynamically generated web content.
Solution : Update to version 0.9.14.005 or newer
See also: http://www.phpgroupware.org/
Threat Level: Medium
Click HERE for more information and discussions on this network vulnerability scan.
|