Back

CVE-2004-2573

PHP remote file inclusion vulnerability in tables_update.inc.php in phpGroupWare 0.9.14.005 and earlier allows remote attackers to execute arbitrary PHP code via an external URL in the appdir parameter.

Published: Dec 31, 2004 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (2)

Vendor Product Version
phpgroupware phpgroupware *
phpgroupware phpgroupware 0.9.14.003

GitHub Security Advisory GHSA-ghxr-vr43-7gg4

PHP remote file inclusion vulnerability in tables_update.inc.php in phpGroupWare 0.9.14.005 and...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 2.64%

Top 16% most likely to be exploited

Threat Score 30.8 / 100

Data Sources

NVD EPSS GitHub