diff options
author | Jacques Vidrine <nectar@FreeBSD.org> | 2005-01-21 14:53:14 +0000 |
---|---|---|
committer | Jacques Vidrine <nectar@FreeBSD.org> | 2005-01-21 14:53:14 +0000 |
commit | 5b916628c0e055686eb0856e74bda5ebf3c6a00d (patch) | |
tree | d45ee4f3254e644f1a3e4e4f133e0affc662007c /security | |
parent | - PassiveTeX support needs more testing - mark the port IGNORE (diff) |
Document a vulnerability in eGroupWare.
Diffstat (limited to 'security')
-rw-r--r-- | security/vuxml/vuln.xml | 24 |
1 files changed, 24 insertions, 0 deletions
diff --git a/security/vuxml/vuln.xml b/security/vuxml/vuln.xml index b86e5679536c..3cdd98f14f74 100644 --- a/security/vuxml/vuln.xml +++ b/security/vuxml/vuln.xml @@ -32,6 +32,30 @@ EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. --> <vuxml xmlns="http://www.vuxml.org/apps/vuxml-1"> + <vuln vid="39953788-6bbb-11d9-8bc9-000a95bc6fae"> + <topic>egroupware -- arbitrary file download in JiNN</topic> + <affects> + <package> + <name>eGroupWare</name> + <range><lt>1.0.0.006</lt></range> + </package> + </affects> + <description> + <body xmlns="http://www.w3.org/1999/xhtml"> + <p>eGroupWare contains a bug in the JiNN component that allows + a remote attacker to download arbitrary files.</p> + </body> + </description> + <references> + <url>http://cvs.sourceforge.net/viewcvs.py/egroupware/jinn/CHANGELOG#rev1.24</url> + <mlist>http://sourceforge.net/mailarchive/forum.php?thread_id=5915445&forum_id=35178</mlist> + </references> + <dates> + <discovery>2004-10-15</discovery> + <entry>2005-01-21</entry> + </dates> + </vuln> + <vuln vid="2c25e762-6bb9-11d9-93db-000a95bc6fae"> <topic>quake2 -- multiple critical vulnerabilities</topic> <affects> |