{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-08-02T00:28:27.775","vulnerabilities":[{"cve":{"id":"CVE-2009-4416","sourceIdentifier":"cve@mitre.org","published":"2009-12-24T16:30:00.483","lastModified":"2026-06-16T23:13:37.593","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Cross-site scripting (XSS) vulnerability in login.php in phpGroupWare 0.9.16.12, and possibly other versions before 0.9.16.014, allows remote attackers to inject arbitrary web script or HTML via an arbitrary parameter whose name begins with the \"phpgw_\" sequence."},{"lang":"es","value":"Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en login.php en phpGroupWare v0.9.16.12, y probablemente otras versiones anteriores a v0.9.16.014, permite a atacantes remotos inyectar código web y HTML de su elección a través de un parámetro elegido cuyo nombre empieza con la secuencia \"phpgw_\"."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:phpgroupware:phpgroupware:0.9.16.12:*:*:*:*:*:*:*","matchCriteriaId":"3C58F242-81C3-4739-B28D-2D2FD8F0DEE1"}]}]}],"references":[{"url":"http://kambing.ui.ac.id/gentoo-portage/www-apps/phpgroupware/files/phpgroupware-SA35519.patch","source":"cve@mitre.org","tags":["Patch"]},{"url":"http://secunia.com/advisories/35519","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"http://svn.savannah.gnu.org/viewvc/branches/Version-0_9_16-branch/login.php?r1=19063&r2=19117&pathrev=19117&sortby=date&root=phpgroupware","source":"cve@mitre.org"},{"url":"http://svn.savannah.gnu.org/viewvc/branches/Version-0_9_16-branch/phpgwapi/doc/CHANGELOG?r1=17045&r2=19117&pathrev=19117&sortby=date&root=phpgroupware","source":"cve@mitre.org"},{"url":"http://svn.savannah.gnu.org/viewvc?view=rev&root=phpgroupware&sortby=date&revision=19117","source":"cve@mitre.org"},{"url":"http://www.openwall.com/lists/oss-security/2009/12/20/1","source":"cve@mitre.org"},{"url":"http://www.osvdb.org/56179","source":"cve@mitre.org"},{"url":"http://www.securityfocus.com/bid/35761","source":"cve@mitre.org"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/51923","source":"cve@mitre.org"},{"url":"http://kambing.ui.ac.id/gentoo-portage/www-apps/phpgroupware/files/phpgroupware-SA35519.patch","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"]},{"url":"http://secunia.com/advisories/35519","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"http://svn.savannah.gnu.org/viewvc/branches/Version-0_9_16-branch/login.php?r1=19063&r2=19117&pathrev=19117&sortby=date&root=phpgroupware","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://svn.savannah.gnu.org/viewvc/branches/Version-0_9_16-branch/phpgwapi/doc/CHANGELOG?r1=17045&r2=19117&pathrev=19117&sortby=date&root=phpgroupware","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://svn.savannah.gnu.org/viewvc?view=rev&root=phpgroupware&sortby=date&revision=19117","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.openwall.com/lists/oss-security/2009/12/20/1","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.osvdb.org/56179","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.securityfocus.com/bid/35761","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/51923","source":"af854a3a-2127-422b-91ae-364da2661108"}]}}]}