CVE-2009-4414

phpgwapi <0.9.16.014 - SQL Injection

Title source: llm
STIX 2.1

Description

SQL injection vulnerability in phpgwapi /inc/class.auth_sql.inc.php in phpGroupWare 0.9.16.12, and possibly other versions before 0.9.16.014, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the passwd parameter to login.php.

References (8)

Core 8
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/56178
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/35519
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/35761
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/51922
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2009/12/20/1

Scores

EPSS 0.0128
EPSS Percentile 67.0%

Details

CWE
CWE-89
Status published
Products (1)
phpgroupware/phpgroupware 0.9.16.012
Published Dec 24, 2009
Tracked Since Feb 18, 2026