CVE-2005-1202
published 2005-05-02CVE-2005-1202: Multiple cross-site scripting (XSS) vulnerabilities in eGroupware before 1.0.0.007 allow remote attackers to inject arbitrary web script or HTML via the (1)…
PriorityP422medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EXPLOIT
EPSS
2.97%
85.6th percentile
Multiple cross-site scripting (XSS) vulnerabilities in eGroupware before 1.0.0.007 allow remote attackers to inject arbitrary web script or HTML via the (1) ab_id, (2) page, (3) type, or (4) lang parameter to index.php or (5) category_id parameter.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| egroupware | egroupware | — | — |
| egroupware | egroupware | — | — |
| egroupware | egroupware | — | — |
| egroupware | egroupware | — | — |
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
Exploit-DB
eGroupWare 1.0 - 'index.php' Multiple Cross-Site Scripting Vulnerabilities
exploitdb·2005-04-18
CVE-2005-1202 eGroupWare 1.0 - 'index.php' Multiple Cross-Site Scripting Vulnerabilities
eGroupWare 1.0 - 'index.php' Multiple Cross-Site Scripting Vulnerabilities
---
source: https://www.securityfocus.com/bid/13212/info
eGroupWare is prone to multiple input validation vulnerabilities. A fixed version is available.
The issues arise due to a failure of the application to properly validate user-supplied input. These issues result in cross-site scripting and SQL injection attacks.
http://egroupware/index.php?menuaction=addressbook.uiaddressbook.edit&ab_id=11[XSS]
http://egroupware/index.php?menuaction=manual.uimanual.view&page=ManualAddressbook[XSS]
http://egroupware/index.php?menuaction=forum.uiforum.post&type=new[XSS]
http://egroupware/wiki/index.php?page=RecentChanges[XSS]
http://egroupware/wiki/index.php?action=history&page=WikkiTikkiTavi&lang=en[XSS]
http://egroupware/i
Exploit-DB
eGroupWare 1.0 - '/sitemgr-site/index.php?category_id' Cross-Site Scripting
exploitdb·2005-04-18
CVE-2005-1202 eGroupWare 1.0 - '/sitemgr-site/index.php?category_id' Cross-Site Scripting
eGroupWare 1.0 - '/sitemgr-site/index.php?category_id' Cross-Site Scripting
---
source: https://www.securityfocus.com/bid/13212/info
eGroupWare is prone to multiple input validation vulnerabilities. A fixed version is available.
The issues arise due to a failure of the application to properly validate user-supplied input. These issues result in cross-site scripting and SQL injection attacks.
http://egroupware/sitemgr/sitemgr-site/?category_id=4[XSS]
No writeups or analysis indexed.
http://marc.info/?l=bugtraq&m=111401760125555&w=2http://secunia.com/advisories/14982http://security.gentoo.org/glsa/glsa-200504-24.xmlhttp://sourceforge.net/project/shownotes.php?release_id=320768http://www.gulftech.org/?node=research&article_id=00069-04202005http://www.osvdb.org/15751http://www.securityfocus.com/bid/13212http://marc.info/?l=bugtraq&m=111401760125555&w=2http://secunia.com/advisories/14982http://security.gentoo.org/glsa/glsa-200504-24.xmlhttp://sourceforge.net/project/shownotes.php?release_id=320768http://www.gulftech.org/?node=research&article_id=00069-04202005http://www.osvdb.org/15751http://www.securityfocus.com/bid/13212
2005-05-02
Published