PHPGroupware 0.9.12 and earlier, when running with the magic_quotes_gpc feature disabled, allows remote attackers to compromise the database via a SQL injection attack.Referenceshttp://archives.neohapsis.com/archives/bugtraq/2002-04/0036.htmlhttp://www.osvdb.org/5153http://www.securityfocus.com/bid/4424http://archives.neohapsis.com/archives/bugtraq/2002-04/0143.htmlhttp://www.iss.net/security_center/static/8755.php