CVE-2004-1385

Publication date 31 December 2004

Last updated 17 July 2025


Ubuntu priority

Description

phpGroupWare 0.9.16.003 and earlier allows remote attackers to gain sensitive information via (1) unexpected characters in the session ID such as shell metacharacters, (2) an invalid appname parameter to preferences.php or (3) an invalid menuaction parameter to index.php, which reveals the web server path in an error message.

Status

Package Ubuntu Release Status
phpgroupware 7.04 feisty
Fixed 0.9.16.010-1
6.10 edgy
Fixed 0.9.16.010-1
6.06 LTS dapper
Fixed 0.9.16.010-1


Access our resources on patching vulnerabilities