Unrated severityNVD Advisory· Published Dec 31, 2004· Updated Apr 16, 2026
CVE-2004-1384
CVE-2004-1384
Description
Multiple cross-site scripting (XSS) vulnerabilities in phpGroupWare 0.9.16.003 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) kp3, (2) type, (3) msg, (4) forum_id, (5) pos, (6) cats_app, (7) cat_id, (8) msgball[msgnum], (9) fldball[acctnum] parameters to index.php or (10) ticket_id to viewticket_details.php.
Affected products
11cpe:2.3:a:phpgroupware:phpgroupware:0.9.12:*:*:*:*:*:*:*+ 10 more
- cpe:2.3:a:phpgroupware:phpgroupware:0.9.12:*:*:*:*:*:*:*
- cpe:2.3:a:phpgroupware:phpgroupware:0.9.13:*:*:*:*:*:*:*
- cpe:2.3:a:phpgroupware:phpgroupware:0.9.14:*:*:*:*:*:*:*
- cpe:2.3:a:phpgroupware:phpgroupware:0.9.14.003:*:*:*:*:*:*:*
- cpe:2.3:a:phpgroupware:phpgroupware:0.9.14.005:*:*:*:*:*:*:*
- cpe:2.3:a:phpgroupware:phpgroupware:0.9.14.006:*:*:*:*:*:*:*
- cpe:2.3:a:phpgroupware:phpgroupware:0.9.14.007:*:*:*:*:*:*:*
- cpe:2.3:a:phpgroupware:phpgroupware:0.9.16.000:*:*:*:*:*:*:*
- cpe:2.3:a:phpgroupware:phpgroupware:0.9.16.002:*:*:*:*:*:*:*
- cpe:2.3:a:phpgroupware:phpgroupware:0.9.16.003:*:*:*:*:*:*:*
- cpe:2.3:a:phpgroupware:phpgroupware:0.9.16_rc1:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- www.gentoo.org/security/en/glsa/glsa-200501-08.xmlnvdPatch
- www.gulftech.orgnvdExploit
- www.securityfocus.com/bid/11952nvdExploitPatch
- marc.infonvd
- exchange.xforce.ibmcloud.com/vulnerabilities/18496nvd
News mentions
0No linked articles in our index yet.