![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
Test ID: | 1.3.6.1.4.1.25623.1.0.809846 |
Category: | Web application abuses |
Title: | Open-Xchange (OX) App Suite Multiple Vulnerabilities -01 (Jan 2017) |
Summary: | Open-Xchange (OX) App Suite is prone to multiple vulnerabilities. |
Description: | Summary: Open-Xchange (OX) App Suite is prone to multiple vulnerabilities. Vulnerability Insight: Multiple flaws exist due to - An improper validation of input passed to 'contact names' parameter. - An improper validation of input passed to 'Users names' parameter. - Script code within hyperlinks at HTML E-Mails is not getting correctly sanitized when using base64 encoded 'data' resources. - An improper validation of XML structure. - Users can provide local file paths to the RSS reader. The response and error code give hints about whether the provided file exists or not. - An improper sanitization of user-supplied input. Vulnerability Impact: Successful exploitation will allow attackers to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected application. This may let the attacker steal cookie-based authentication credentials and bypass certain security restrictions to perform unauthorized actions. Attackers can also exploit this issue to obtain sensitive information that may aid in further attacks. Affected Software/OS: Open-Xchange (OX) App Suite version 7.8.2-rev0 - 7.8.2-rev7, 7.6.2-rev0 - 7.6.2-rev46. Solution: Update to version 7.8.2-rev8, or 7.6.2-rev47, or later. CVSS Score: 4.3 CVSS Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N |
Cross-Ref: |
Common Vulnerability Exposure (CVE) ID: CVE-2016-6847 BugTraq ID: 93457 http://www.securityfocus.com/bid/93457 Common Vulnerability Exposure (CVE) ID: CVE-2016-6848 BugTraq ID: 93460 http://www.securityfocus.com/bid/93460 Common Vulnerability Exposure (CVE) ID: CVE-2016-6850 Common Vulnerability Exposure (CVE) ID: CVE-2016-6852 BugTraq ID: 93459 http://www.securityfocus.com/bid/93459 Common Vulnerability Exposure (CVE) ID: CVE-2016-6842 Common Vulnerability Exposure (CVE) ID: CVE-2016-6843 Common Vulnerability Exposure (CVE) ID: CVE-2016-6844 Common Vulnerability Exposure (CVE) ID: CVE-2016-6845 |
Copyright | Copyright (C) 2017 Greenbone AG |
This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |