Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2016-2840
Description:An issue was discovered in Open-Xchange Server 6 / OX AppSuite before 7.8.0-rev26. The "session" parameter for file-download requests can be used to inject script code that gets reflected through the subsequent status page. Malicious script code can be executed within a trusted domain's context. While no OX App Suite specific data can be manipulated, the vulnerability can be exploited without being authenticated and therefore used for social engineering attacks, stealing cookies or redirecting from trustworthy to malicious hosts.
Test IDs: 1.3.6.1.4.1.25623.1.0.809851  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2016-2840
Bugtraq: 20160402 Open-Xchange Security Advisory 2016-04-02 (Google Search)
http://www.securityfocus.com/archive/1/537959/100/0/threaded
http://www.securitytracker.com/id/1035469




© 1998-2025 E-Soft Inc. All rights reserved.