phpGroupWare prima 0.9.16.002 trasmette la (1) intestazione amministratore e password di impostazione (2) in chiaro via cookie, che permette aggressori remoti di password sniff. |
http://www.securityfocus.com/bid/10895 http://web.archive.org/web/20040920024328/http://www.phpgroupware.org/ http://www.osvdb.org/8354 https://exchange.xforce.ibmcloud.com/vulnerabilities/16970 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-2578 |
Vulnerabilità: CVE-2004-2578
