CVE-2009-4416
Published Dec 24, 2009
Last updated 7 years ago
Overview
- Description
- Cross-site scripting (XSS) vulnerability in login.php in phpGroupWare 0.9.16.12, and possibly other versions before 0.9.16.014, allows remote attackers to inject arbitrary web script or HTML via an arbitrary parameter whose name begins with the "phpgw_" sequence.
- Source
- cve@mitre.org
- NVD status
- Modified
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 4.3
- Impact score
- 2.9
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:N/I:P/A:N
Weaknesses
- nvd@nist.gov
- CWE-79
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:phpgroupware:phpgroupware:0.9.16.12:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3C58F242-81C3-4739-B28D-2D2FD8F0DEE1" } ], "operator": "OR" } ] } ]