Vulnerability Assessment & Network Security Forums



If through a vulnerability assessment, a network security issue is detected for the vulnerability below, applying the appropriate security patches in a timely matter is very important.  If you have detected that your system has already been compromised, following CERT's Network Security recovery document will assist with recommended steps for system recovery.


Home >> Browse Vulnerability Assessment Database >> Debian Local Security Checks >> [DSA798] DSA-798-1 phpgroupware


Vulnerability Assessment Details

[DSA798] DSA-798-1 phpgroupware

Vulnerability Assessment Summary
DSA-798-1 phpgroupware

Detailed Explanation for this Vulnerability Assessment

Several vulnerabilities have been discovered in phpgroupware, a web
based groupware system written in PHP. The Common Vulnerabilities and
Exposures project identifies the following problems:
Stefan Esser discovered another vulnerability in the XML-RPC
libraries that permits injection of arbitrary PHP code into eval()
statements. The XMLRPC component has been disabled.
Alexander Heidenreich discovered a cross-site scripting problem
in the tree view of FUD Forum Bulletin Board Software, which is
also present in phpgroupware.
A global cross-site scripting fix has also been included that
protects against potential malicious scripts embedded in CSS and
xmlns in various parts of the application and modules.
This update also contains a postinst bugfix that has been approved for
the next update to the stable release.
For the old stable distribution (woody) these problems don't apply.
For the stable distribution (sarge) these problems have been fixed in
version 0.9.16.005-3.sarge2.
For the unstable distribution (sid) these problems have been fixed in
version 0.9.16.008.
We recommend that you upgrade your phpgroupware packages.


Solution : http://www.debian.org/security/2005/dsa-798
Network Security Threat Level: High

Networks Security ID:

Vulnerability Assessment Copyright: This script is (C) 2007 Michel Arboi

Cables, Connectors


Apple Macintosh Plus 1MB M0001A Vintage Computer Boots Up / Floppy Disk Stuck picture

Apple Macintosh Plus 1MB M0001A Vintage Computer Boots Up / Floppy Disk Stuck

$99.99



Apple Macintosh Classic M1420 Vintage Desktop Computer Model Macintosh Classic picture

Apple Macintosh Classic M1420 Vintage Desktop Computer Model Macintosh Classic

$100.00



Vintage 1998 iMac G3 M4984 Mac OS + Keyboard Working but Needs Some Repair Read picture

Vintage 1998 iMac G3 M4984 Mac OS + Keyboard Working but Needs Some Repair Read

$295.00



Apple Power Macintosh PowerPC 7300/200 VTG w Keyboard Mouse Storage Drive Read picture

Apple Power Macintosh PowerPC 7300/200 VTG w Keyboard Mouse Storage Drive Read

$199.99



Macintosh MacTerminal M0521 Version 1.0. Vintage Apple software 1984 Sealed picture

Macintosh MacTerminal M0521 Version 1.0. Vintage Apple software 1984 Sealed

$129.99



Vintage 1992 Mac System 7.1P1 Apple Software 3.5” Floppy Disks NOS picture

Vintage 1992 Mac System 7.1P1 Apple Software 3.5” Floppy Disks NOS

$35.00



185--Sonnet Crescendo G3 PPCG3-375-5-K-06 G3 Add-On Card for Vintage Mac picture

185--Sonnet Crescendo G3 PPCG3-375-5-K-06 G3 Add-On Card for Vintage Mac

$90.00



READ - UNTESTED Apple Macintosh PowerBook 160 M4550 Vintage Laptop picture

READ - UNTESTED Apple Macintosh PowerBook 160 M4550 Vintage Laptop

$299.00



Mixed Lot Vintage Mac Windows media / Graphics / Sound Software - CDs 37 Pieces picture

Mixed Lot Vintage Mac Windows media / Graphics / Sound Software - CDs 37 Pieces

$40.99



Vintage Edmark TouchWindow for Macintosh DeskTop Computer Touch Window Never Usd picture

Vintage Edmark TouchWindow for Macintosh DeskTop Computer Touch Window Never Usd

$63.99



Discussions

No Discussions have been posted on this vulnerability.