An open redirect in eGroupware version 1.8.001.20110421 can be exploited to redirect users to an arbitrary URL.
b4a29e3964e1d7bd72995d10043cf6c74cf999a044fb3fe26884221a0473da93
------------------------------------------------------------------------
Software................eGroupware 1.8.001.20110421
Vulnerability...........Open Redirect
Threat Level............Low (1/5)
Download................http://www.egroupware.org/
Discovery Date..........5/19/2011
Tested On...............Windows Vista + XAMPP
------------------------------------------------------------------------
Author..................AutoSec Tools
Site....................http://www.autosectools.com/
Email...................John Leitch <john@autosectools.com>
------------------------------------------------------------------------
--Description--
An open redirect in eGroupware 1.8.001.20110421 can be exploited to
redirect users to an arbitrary URL.
--PoC--
http://localhost/egroupware/phpgwapi/ntlm/index.php?forward=http://www.autosectools.com/