CVE

CVE-2004-2578

Severity:
Pending analysis
Type:
Unavailable / Other
Publication date:
31/12/2004
Last modified:
11/07/2017

Description

phpGroupWare before 0.9.16.002 transmits the (1) header admin and (2) setup passwords in plaintext via cookies, which allows remote attackers to sniff passwords.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:phpgroupware:phpgroupware:0.9.1:*:*:*:*:*:*:*
cpe:2.3:a:phpgroupware:phpgroupware:0.9.2:*:*:*:*:*:*:*
cpe:2.3:a:phpgroupware:phpgroupware:0.9.3:*:*:*:*:*:*:*
cpe:2.3:a:phpgroupware:phpgroupware:0.9.4:*:*:*:*:*:*:*
cpe:2.3:a:phpgroupware:phpgroupware:0.9.5:*:*:*:*:*:*:*
cpe:2.3:a:phpgroupware:phpgroupware:0.9.6:*:*:*:*:*:*:*
cpe:2.3:a:phpgroupware:phpgroupware:0.9.7:*:*:*:*:*:*:*
cpe:2.3:a:phpgroupware:phpgroupware:0.9.8:*:*:*:*:*:*:*
cpe:2.3:a:phpgroupware:phpgroupware:0.9.9:*:*:*:*:*:*:*
cpe:2.3:a:phpgroupware:phpgroupware:0.9.9_pl1:*:*:*:*:*:*:*
cpe:2.3:a:phpgroupware:phpgroupware:0.9.10:*:*:*:*:*:*:*
cpe:2.3:a:phpgroupware:phpgroupware:0.9.12:*:*:*:*:*:*:*
cpe:2.3:a:phpgroupware:phpgroupware:0.9.13:*:*:*:*:*:*:*
cpe:2.3:a:phpgroupware:phpgroupware:0.9.14.003:*:*:*:*:*:*:*
cpe:2.3:a:phpgroupware:phpgroupware:0.9.14.005:*:*:*:*:*:*:*