phpGroupWare Unspecified Remote File Inclusion

high Nessus Plugin ID 14294

Synopsis

Arbitrary code may be run on the remote host.

Description

The version of PhpGroupWare hosted on the remote web server has a vulnerability that may permit remote attackers, without prior authentication, to include and execute malicious PHP scripts.

Remote users may influence URI variables to include a malicious PHP script on a remote system, it is possible to cause arbitrary PHP code to be executed.

Solution

Update to phpGroupWare version 0.9.14.006 or later.

Plugin Details

Severity: High

ID: 14294

File Name: phpgroupware_remote_file_include.nasl

Version: 1.21

Type: remote

Family: CGI abuses

Published: 8/17/2004

Updated: 4/11/2022

Configuration: Enable thorough checks

Supported Sensors: Nessus

Risk Information

CVSS v2

Risk Factor: High

Base Score: 7.5

Temporal Score: 5.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Information

CPE: cpe:/a:phpgroupware:phpgroupware

Exploit Available: true

Exploit Ease: No exploit is required

Reference Information

BID: 8265