Summary
The remote host is missing an update to phpgroupware announced via advisory DSA 898-1.
Several vulnerabilities have been discovered in phpsysinfo, a PHP based host information application. The Common Vulnerabilities and Exposures project identifies the following problems:
CVE-2005-0870
Maksymilian Arciemowicz discoverd several cross site scripting problems, of which not all were fixed in DSA 724.
CVE-2005-3347
Christopher Kunz discovered that local variables get overwritten unconditionally and are trusted later, which could lead to the inclusion of arbitrary files.
CVE-2005-3348
Christopher Kunz discovered that user-supplied input is used unsanitised, causing a HTTP Response splitting problem.
For the old stable distribution (woody) these problems have been fixed in version 0.9.14-0.RC3.2.woody5.
Solution
For the stable distribution (sarge) these problems have been fixed in version 0.9.16.005-3.sarge4.
For the unstable distribution (sid) these problems have been fixed in version 0.9.16.008-2.
We recommend that you upgrade your phpgroupware packages.
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%20898-1
Severity
Classification
-
CVE CVE-2005-0870, CVE-2005-3347, CVE-2005-3348 -
CVSS Base Score: 6.8
AV:N/AC:M/Au:N/C:P/I:P/A:P
Related Vulnerabilities