Maksymilian Arciemowicz discoverd several cross site scripting
problems in phpsysinfo, which are also present in the imported
version in egroupware and of which not all were fixed in DSA 724.
CVE-2005-2600
Alexander Heidenreich discovered a cross-site scripting problem in
the tree view of FUD Forum Bulletin Board Software, which is also
present in egroupwre and allows remote attackers to read private
posts via a modified mid parameter.
CVE-2005-3347
Christopher Kunz discovered that local variables get overwritten
unconditionally in phpsyinfo, which are also present in
egroupware, and are trusted later, which could lead to the
inclusion of arbitrary files.
CVE-2005-3348
Christopher Kunz discovered that user-supplied input is used
unsanitised in phpsyinfo and imported in egroupware, causing a
HTTP Response splitting problem.
The old stable distribution (woody) does not contain egroupware packages.
For the stable distribu...
Get the latest Linux and open source security news straight to your inbox.