Total vulnerabilities in the database
Multiple directory traversal vulnerabilities in phpGroupWare 0.9.16.12, and possibly other versions before 0.9.16.014, allow remote attackers to (1) read arbitrary files via the csvfile parameter to addressbook/csv_import.php, or (2) include and execute arbitrary local files via the conv_type parameter in addressbook/inc/class.uiXport.inc.php.
Software | From | Fixed in |
---|---|---|
phpgroupware / phpgroupware | 0.9.16.12 | 0.9.16.12.x |