Exploitation Summary
EIP tracks 1 public exploit for CVE-2004-1385. PoCs published by GulfTech Security.
AI-analyzed exploit summary The provided text describes multiple SQL injection and cross-site scripting vulnerabilities in PHPGroupWare 0.9.16.003. It includes example URLs demonstrating how an attacker could exploit these vulnerabilities by injecting malicious SQL queries or script code.
Description
phpGroupWare 0.9.16.003 and earlier allows remote attackers to gain sensitive information via (1) unexpected characters in the session ID such as shell metacharacters, (2) an invalid appname parameter to preferences.php or (3) an invalid menuaction parameter to index.php, which reveals the web server path in an error message.
Exploits (1)
The provided text describes multiple SQL injection and cross-site scripting vulnerabilities in PHPGroupWare 0.9.16.003. It includes example URLs demonstrating how an attacker could exploit these vulnerabilities by injecting malicious SQL queries or script code.