CVE-2010-0404
Last modified
CVE-2010-0404 is a vulnerability of currently unknown severity. Multiple SQL injection vulnerabilities in phpGroupWare (phpgw) before 0.9.16.016 allow remote attackers to execute arbitrary SQL commands via unspecified parameters to (1) class.sessions_db.inc.php, (2) class.translation_sql.inc.php, or (3) class.auth_sql.inc.php in phpgwapi/inc/.. EPSS estimates a 2.33% chance of exploitation in the next 30 days.
Description
Multiple SQL injection vulnerabilities in phpGroupWare (phpgw) before 0.9.16.016 allow remote attackers to execute arbitrary SQL commands via unspecified parameters to (1) class.sessions_db.inc.php, (2) class.translation_sql.inc.php, or (3) class.auth_sql.inc.php in phpgwapi/inc/.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Phpgroupware | Phpgroupware | <= 0.9.16.015 |
| Phpgroupware | Phpgroupware | 0.9.16 |
| Phpgroupware | Phpgroupware | 0.9.16.000 |
| Phpgroupware | Phpgroupware | 0.9.16.001 |
| Phpgroupware | Phpgroupware | 0.9.16.002 |
| Phpgroupware | Phpgroupware | 0.9.16.003 |
| Phpgroupware | Phpgroupware | 0.9.16.005 |
| Phpgroupware | Phpgroupware | 0.9.16.010 |
| Phpgroupware | Phpgroupware | 0.9.16.011 |
| Phpgroupware | Phpgroupware | 0.9.16.012 |
| Phpgroupware | Phpgroupware | 0.9.16.014 |
References
- http://download.phpgroupware.org/Patch, Vendor Advisory
- http://secunia.com/advisories/39665Vendor Advisory
- http://secunia.com/advisories/39731Vendor Advisory
- http://www.vupen.com/english/advisories/2010/1145Vendor Advisory
- http://www.vupen.com/english/advisories/2010/1146Vendor Advisory
- http://download.phpgroupware.org/Patch, Vendor Advisory
- http://secunia.com/advisories/39665Vendor Advisory
- http://secunia.com/advisories/39731Vendor Advisory
- http://www.vupen.com/english/advisories/2010/1145Vendor Advisory
- http://www.vupen.com/english/advisories/2010/1146Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2010-0404?
How severe is CVE-2010-0404?
How do I fix CVE-2010-0404?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2010
- CVE-2010-0397The xmlrpc extension in PHP 5.3.1 does not properly handle a…
- CVE-2010-0398The init script in autokey before 0.61.3-2 allows local atta…6.5
- CVE-2010-0400SQL injection vulnerability in lib/user.php in mahara 1.0.4 …
- CVE-2010-0401OpenTTD before 1.0.1 accepts a company password for authenti…
- CVE-2010-0402OpenTTD before 1.0.1 does not properly validate index values…
- CVE-2010-0403Directory traversal vulnerability in about.php in phpGroupWa…
- CVE-2010-0405Integer overflow in the BZ2_decompress function in decompres…
- CVE-2010-0406OpenTTD before 1.0.1 allows remote attackers to cause a deni…
- CVE-2010-0407Multiple buffer overflows in the MSGFunctionDemarshall funct…
- CVE-2010-0408The ap_proxy_ajp_request function in mod_proxy_ajp.c in mod_…
- CVE-2010-0409Buffer overflow in the GMIME_UUENCODE_LEN macro in gmime/gmi…
- CVE-2010-0410drivers/connector/connector.c in the Linux kernel before 2.6…
Are you affected by CVE-2010-0404?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
