phpGroupWare: Various vulnerabilities — GLSA 200501-08 Multiple vulnerabilities have been discovered in phpGroupWare that could lead to information disclosure or remote compromise. Affected packages Package www-apps/phpgroupware on all architectures Affected versions < 0.9.16.004 Unaffected versions >= 0.9.16.004 Background phpGroupWare is a web-based suite of group applications including a calendar, todo-list, addressbook, email, wiki, news headlines, and a file manager. Description Several flaws were discovered in phpGroupWare making it vulnerable to cross-site scripting attacks, SQL injection, and full path disclosure. Impact These vulnerabilities could allow an attacker to perform cross-site scripting attacks, execute SQL queries, and disclose the full path of the web directory. Workaround There is no known workaround at this time. Resolution All phpGroupWare users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose ">=www-apps/phpgroupware-0.9.16.004" Note: Users with the vhosts USE flag set should manually use webapp-config to finalize the update. References BugTraq Advisory CVE-2004-1383 CVE-2004-1384 CVE-2004-1385