Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 544
Alerts This Week
Warning Icon 1 544

Gentoo GLSA: 200812-20 High Risk: phpCollab Remote Code Injection

gentoo
Calendar Grey December 21, 2008
Scroller Gentoo
Gentoo GLSA 202301-15 outlines severe vulnerabilities in phpCollab that enable remote command execution and unauthorized SQL access.
Multiple vulnerabilities have been discovered in phpCollab allowing for remote injection of shell commands, PHP code and SQL statements.

Summary

Gentoo Linux Security Advisory GLSA 200812-20 https://security.gentoo.org/ Severity: High Title: phpCollab: Multiple vulnerabilities Date: December 21, 2008 Bugs: #235052 ID: 200812-20

Synopsis ======= Multiple vulnerabilities have been discovered in phpCollab allowing for remote injection of shell commands, PHP code and SQL statements.
Background ========= phpCollab is a web-enabled groupware and project management software written in PHP. It uses SQL-based database backends.
Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 www-apps/phpcollab <= 2.5_rc3 Vulnerable! ------------------------------------------------------------------- NOTE: Certain packages are still vulnerable. Users should migrate to another package if one is available or wait for the existing packages to be marked stable by their architecture maintainers.
========== Multiple vulnerabilities have been found in phpCollab:
* rgod reported that data sent to general/sendpassword...

Read the Full Advisory

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround