CVE detail
CVE-2004-1384 — CVE-2004-1384
Published 2004-12-31 · Modified 2026-06-16 · Vendor phpgroupware · Product phpgroupware · Source nvd
UNKNOWN
severity
CVSS-derived band
0.0404
EPSS probability
exploitation probability, 30d
90.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
Multiple cross-site scripting (XSS) vulnerabilities in phpGroupWare 0.9.16.003 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) kp3, (2) type, (3) msg, (4) forum_id, (5) pos, (6) cats_app, (7) cat_id, (8) msgball[msgnum], (9) fldball[acctnum] parameters to index.php or (10) ticket_id to viewticket_details.php.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References