Title : eGroupWare "_bad_protocol_once()" Security Bypass Vulnerability VUPEN ID : VUPEN/ADV-2008-0989 CVE ID : CVE-2008-1502
Rated as : Low Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-03-25
Technical Description
A vulnerability has been identified in eGroupWare, which could be exploited by attackers to bypass security restrictions. This issue is caused by an input validation error in the "_bad_protocol_once()" [phpgwapi/inc/class.kses.inc.php] function when processing user-supplied data, which could be exploited by attackers to bypass the HTML filters.