![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
CVE ID: | CVE-2016-2840 |
Description: | An issue was discovered in Open-Xchange Server 6 / OX AppSuite before 7.8.0-rev26. The "session" parameter for file-download requests can be used to inject script code that gets reflected through the subsequent status page. Malicious script code can be executed within a trusted domain's context. While no OX App Suite specific data can be manipulated, the vulnerability can be exploited without being authenticated and therefore used for social engineering attacks, stealing cookies or redirecting from trustworthy to malicious hosts. |
Test IDs: | 1.3.6.1.4.1.25623.1.0.809851 |
Cross References: |
Common Vulnerability Exposure (CVE) ID: CVE-2016-2840 Bugtraq: 20160402 Open-Xchange Security Advisory 2016-04-02 (Google Search) http://www.securityfocus.com/archive/1/537959/100/0/threaded http://www.securitytracker.com/id/1035469 |