HIGH · 7.5

CVE-2004-0016

The calendar module for phpgroupware 0.9.14 does not enforce the "save extension" feature for holiday files, which allows remote attackers to create and execute PHP files.

Vulnerability Description

The calendar module for phpgroupware 0.9.14 does not enforce the "save extension" feature for holiday files, which allows remote attackers to create and execute PHP files.

CVSS Score

7.5

HIGH

AV:N/AC:L/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
PhpgroupwarePhpgroupware0.9.14

References

FAQ

What is CVE-2004-0016?

CVE-2004-0016 is a vulnerability with a CVSS score of 7.5 (HIGH). The calendar module for phpgroupware 0.9.14 does not enforce the "save extension" feature for holiday files, which allows remote attackers to create and execute PHP files.

How severe is CVE-2004-0016?

CVE-2004-0016 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2004-0016?

Check the references section above for vendor advisories and patch information. Affected products include: Phpgroupware Phpgroupware.