CVE-2004-2578
phpGroupWare before 0.9.16.002 transmits the (1) header admin and (2) setup passwords in plaintext via cookies, which allows remote attackers to sniff passwords.
Date published : 2005-11-28
http://www.securityfocus.com/bid/10895
http://web.archive.org/web/20040920024328/http://www.phpgroupware.org/
