Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

Gentoo GLSA: 200812-20 High Risk: phpCollab Remote Code Injection

gentoo
Calendar Grey December 21, 2008
Dist Gentoo Esm H88
Gentoo GLSA 202301-15 outlines severe vulnerabilities in phpCollab that enable remote command execution and unauthorized SQL access.
Multiple vulnerabilities have been discovered in phpCollab allowing for remote injection of shell commands, PHP code and SQL statements.

Summary

Gentoo Linux Security Advisory GLSA 200812-20 https://security.gentoo.org/ Severity: High Title: phpCollab: Multiple vulnerabilities Date: December 21, 2008 Bugs: #235052 ID: 200812-20

Synopsis ======= Multiple vulnerabilities have been discovered in phpCollab allowing for remote injection of shell commands, PHP code and SQL statements.
Background ========= phpCollab is a web-enabled groupware and project management software written in PHP. It uses SQL-based database backends.
Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 www-apps/phpcollab <= 2.5_rc3 Vulnerable! ------------------------------------------------------------------- NOTE: Certain packages are still vulnerable. Users should migrate to another package if one is available or wait for the existing packages to be marked stable by their architecture maintainers.
========== Multiple vulnerabilities have been found in phpCollab:
* rgod reported that data sent to general/sendpassword...

Read the Full Advisory

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns


Warning: Undefined array key "advisory_info" in /var/www/www.linuxsecurity.com-443/html/tmp/regularlabs/custom_php/3760012_4c9dbbdde36eef04251a4ced7eac4df9 on line 11

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround

Related News

Your message here