CVE-2013-7142
https://notcve.org/view.php?id=CVE-2013-7142
17 Jan 2014 — Cross-site scripting (XSS) vulnerability in Open-Xchange (OX) AppSuite 7.4.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified oAuth API functions. Vulnerabilidad XSS en Open-Xchange (OX) AppSuite v7.4.1 y anteriores permite a atacantes remotos inyectar secuencias de comandos web o HTML arbitrarias a través de funciones oAuth no especificadas de la API. • http://osvdb.org/102193 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2013-7143
https://notcve.org/view.php?id=CVE-2013-7143
17 Jan 2014 — Cross-site scripting (XSS) vulnerability in Open-Xchange (OX) AppSuite 7.4.1 allows remote attackers to inject arbitrary web script or HTML via the title in a mail filter rule. Vulnerabilidad XSS en Open-Xchange (OX) AppSuite v7.4.1 permite a atacantes remotos inyectar secuencias de comandos web o HTML arbitrarias a través del título en una regla de filtrado de correo. • http://seclists.org/bugtraq/2014/Jan/57 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2013-7140
https://notcve.org/view.php?id=CVE-2013-7140
17 Jan 2014 — XML External Entity (XXE) vulnerability in the CalDAV interface in Open-Xchange (OX) AppSuite 7.4.1 and earlier allows remote authenticated users to read portions of arbitrary files via vectors related to the SAX builder and the WebDAV interface. NOTE: this issue has been labeled as both absolute path traversal and XXE, but the root cause may be XXE, since XXE can be exploited to conduct absolute path traversal and other attacks. Vulnerabilidad en entidades externas XML (XXE) en la interfaz de CalDAV en Ope... • http://seclists.org/bugtraq/2014/Jan/57 •
CVE-2013-6997
https://notcve.org/view.php?id=CVE-2013-6997
06 Jan 2014 — Multiple cross-site scripting (XSS) vulnerabilities in Open-Xchange (OX) AppSuite 7.4.0 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) an HTML email with crafted CSS code containing wildcards or (2) office documents containing "crafted hyperlinks with script URL handlers." Multiple cross-site scripting (XSS) en Open-Xchange (OX) AppSuite 7.4.0 y anteriores que permite a atacantes remotos inyectar secuencias de comandos web o HTML a través de (1) un correo electrónico HTML ... • http://software.open-xchange.com/OX6/doc/Release_Notes_for_Public_Patch_Release_1766_7.4.0_Rev21_2013_12_13.pdf • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2013-6009
https://notcve.org/view.php?id=CVE-2013-6009
03 Oct 2013 — CRLF injection vulnerability in Open-Xchange AppSuite before 7.2.2, when using AJP in certain conditions, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the ajax/defer servlet. Vulnerabilidad de inyección CRLF en Open-Xchange AppSuite anterior a la versión 7.2.2, cuando se usa AJP en ciertas condiciones, permite a atacantes remotos inyectar cabeceras HTTP arbitrarias y llevar a cabo ataques de división de respuestas HTTP a través del servlet ajax/def... • http://www.securityfocus.com/archive/1/528940 • CWE-94: Improper Control of Generation of Code ('Code Injection') •
CVE-2013-5690
https://notcve.org/view.php?id=CVE-2013-5690
30 Sep 2013 — Multiple cross-site scripting (XSS) vulnerabilities in Open-Xchange AppSuite before 7.2.2 allow remote authenticated users to inject arbitrary web script or HTML via (1) content with the text/xml MIME type or (2) the Status comment field of an appointment. Múltiples vulnerabilidades XSS en Open-Xchange AppSuite anterior a v7.2.2 permite a usuarios autenticados remotamente inyectar secuencias de comandos web o HTML arbitrarias a través de (1) contenido con el tipo text/xml MIME o (2) el campo comentario de S... • http://www.securityfocus.com/archive/1/528940 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2013-5698
https://notcve.org/view.php?id=CVE-2013-5698
05 Sep 2013 — Cross-site scripting (XSS) vulnerability in Open-Xchange AppSuite and Server before 6.22.0 rev16, 6.22.1 before rev19, 7.0.1 before rev7, 7.0.2 before rev11, and 7.2.0 before rev8 allows remote authenticated users to inject arbitrary web script or HTML via a delivery=view action, aka Bug ID 26373, a different vulnerability than CVE-2013-3106. Vulnerabilidad Cross-site scripting (XSS) en Open-Xchange AppSuite y Server anterior a v6.22.0 rev16, v6.22.1 anterior a rev19, v7.0.1 anterior a rev7, v7.0.2 anterior... • http://archives.neohapsis.com/archives/bugtraq/2013-06/0012.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2013-3106
https://notcve.org/view.php?id=CVE-2013-3106
03 Jun 2013 — Multiple cross-site scripting (XSS) vulnerabilities in Open-Xchange AppSuite and Server before 6.20.7 rev18, 6.22.0 before rev16, 6.22.1 before rev19, 7.0.1 before rev7, 7.0.2 before rev11, and 7.2.0 before rev8 allow remote attackers to inject arbitrary web script or HTML via (1) embedded VBScript, (2) object/data Base64 content, (3) a Content-Type header, or (4) UTF-16 encoding, aka Bug IDs 25957, 26237, 26243, and 26244. Múltiples vulnerabilidades XSS en Open-Xchange AppSuite y Server anterior a 6.20.7 r... • http://archives.neohapsis.com/archives/bugtraq/2013-06/0012.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2013-2582
https://notcve.org/view.php?id=CVE-2013-2582
17 Apr 2013 — CRLF injection vulnerability in the redirect servlet in Open-Xchange AppSuite and Server before 6.22.0 rev15, 6.22.1 before rev17, 7.0.1 before rev6, and 7.0.2 before rev7 allows remote attackers to inject arbitrary HTTP headers and conduct open redirect attacks by leveraging improper sanitization of whitespace characters. Vulnerabilidad de inyección CRLF en el servlet para redirigir en Open-Xchange AppSuite y Server anterior a v6.22.0 rev15, v6.22.1 anterior a rev17, v7.0.1 anterior a rev6, y v7.0.2 anteri... • http://archives.neohapsis.com/archives/bugtraq/2013-04/0183.html • CWE-94: Improper Control of Generation of Code ('Code Injection') •
CVE-2013-2583
https://notcve.org/view.php?id=CVE-2013-2583
17 Apr 2013 — Multiple cross-site scripting (XSS) vulnerabilities in Open-Xchange AppSuite and Server before 6.20.7 rev16, 6.22.0 before rev15, 6.22.1 before rev17, 7.0.1 before rev6, and 7.0.2 before rev7 allow remote attackers to inject arbitrary web script or HTML via (1) a javascript: URL, (2) malformed nested SCRIPT elements, (3) a mail signature, or (4) JavaScript code within an image file. Múltiples vulnerabilidades de cross-site scripting (XSS) en Open-Xchange AppSuite y Server anterior a v6.20.7 rev16, v6.22.0 a... • http://archives.neohapsis.com/archives/bugtraq/2013-04/0183.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •