CVE-2004-1383
phpGroupWare 0.9.16.003 - SQL Injection via Multiple Parameters
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2004-1383. PoCs published by GulfTech Security.
AI-analyzed exploit summary The provided text describes multiple input validation vulnerabilities in PHPGroupWare, including SQL injection and cross-site scripting (XSS) issues. It outlines potential impacts such as unauthorized data access and credential theft but does not include functional exploit code.
Description
Multiple SQL injection vulnerabilities in phpGroupWare 0.9.16.003 and earlier allow remote attackers to execute arbitrary SQL statements via the (1) order, (2) project_id, (3) pro_main, or (4) hours_id parameters to index.php or (5) ticket_id to viewticket_details.php.
Exploits (1)
The provided text describes multiple input validation vulnerabilities in PHPGroupWare, including SQL injection and cross-site scripting (XSS) issues. It outlines potential impacts such as unauthorized data access and credential theft but does not include functional exploit code.