Vulnerability Description
The calendar module for phpgroupware 0.9.14 does not enforce the "save extension" feature for holiday files, which allows remote attackers to create and execute PHP files.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Phpgroupware | Phpgroupware | 0.9.14 |
References
- http://www.debian.org/security/2004/dsa-419PatchVendor Advisory
- http://www.osvdb.org/6860
- http://www.securityfocus.com/bid/9387Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/13489
- http://www.debian.org/security/2004/dsa-419PatchVendor Advisory
- http://www.osvdb.org/6860
- http://www.securityfocus.com/bid/9387Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/13489
FAQ
What is CVE-2004-0016?
CVE-2004-0016 is a vulnerability with a CVSS score of 7.5 (HIGH). The calendar module for phpgroupware 0.9.14 does not enforce the "save extension" feature for holiday files, which allows remote attackers to create and execute PHP files.
How severe is CVE-2004-0016?
CVE-2004-0016 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2004-0016?
Check the references section above for vendor advisories and patch information. Affected products include: Phpgroupware Phpgroupware.