Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.809847
Category:Web application abuses
Title:Open-Xchange (OX) App Suite Multiple Vulnerabilities -02 (Jan 2017)
Summary:Open-Xchange (OX) App Suite is prone to multiple vulnerabilities.
Description:Summary:
Open-Xchange (OX) App Suite is prone to multiple vulnerabilities.

Vulnerability Insight:
Multiple flaws exist due to

- An improper validation of input passed to API calls.

- An improper validation of input passed RSS reader of App Suite.

- The content sanitizer component has an issue with filtering malicious content
in case invalid HTML code is provided.

Vulnerability Impact:
Successful exploitation will allow attackers
to execute arbitrary script code in the browser of an unsuspecting user in the
context of the affected application. This may let the attacker steal cookie-based
authentication credentials and bypass certain security restrictions to perform
unauthorized actions, insert and display spoofed content, which may aid in
further attacks.

Affected Software/OS:
Open-Xchange (OX) App Suite versions
7.6.2-rev0 - 7.6.2-rev53,
7.6.3-rev0 - 7.6.3-rev10,
7.8.0-rev0 - 7.8.0-rev29,
7.8.1-rev0 - 7.8.1-rev10

Solution:
Update to version 7.6.2-rev54, or 7.6.3-rev11, or 7.8.0-rev30, or 7.8.1-rev11, or later.

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:N/A:N

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2016-4046
Bugtraq: 20160622 Open-Xchange Security Advisory 2016-06-22 (Google Search)
http://www.securityfocus.com/archive/1/538732/100/0/threaded
http://www.securitytracker.com/id/1036157
Common Vulnerability Exposure (CVE) ID: CVE-2016-4045
Common Vulnerability Exposure (CVE) ID: CVE-2016-4026
CopyrightCopyright (C) 2017 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.