CVE-2004-2578 Information

Description

phpGroupWare before 0.9.16.002 transmits the (1) header admin and (2) setup passwords in plaintext via cookies which allows remote attackers to sniff passwords.

Reference

http://web.archive.org/web/20040920024328/http://www.phpgroupware.org/ http://www.osvdb.org/8354 http://www.securityfocus.com/bid/10895 https://exchange.xforce.ibmcloud.com/vulnerabilities/16970

Share on: