CVE-2016-1215
https://notcve.org/view.php?id=CVE-2016-1215
Cross-site scripting (XSS) vulnerability in the "User details" function in Cybozu Garoon before 4.2.2. Vulnerabilidad XSS en la función "User details" en Cybozu Garoon en versiones anteriores a 4.2.2. • http://jvn.jp/en/jp/JVN67595539/index.html http://jvndb.jvn.jp/en/contents/2016/JVNDB-2016-000144.html http://www.securityfocus.com/bid/92601 https://support.cybozu.com/ja-jp/article/9223 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2016-1220
https://notcve.org/view.php?id=CVE-2016-1220
Cybozu Garoon before 4.2.2 does not properly restrict access. Cybozu Garoon en versiones anteriores a 4.2.2 no restringe correctamente el acceso. • http://jvn.jp/en/jp/JVN93411577/index.html http://jvndb.jvn.jp/en/contents/2016/JVNDB-2016-000149.html http://www.securityfocus.com/bid/92599 https://support.cybozu.com/ja-jp/article/9407 • CWE-284: Improper Access Control •
CVE-2016-1219
https://notcve.org/view.php?id=CVE-2016-1219
Cybozu Garoon before 4.2.2 allows remote attackers to bypass login authentication via vectors related to API use. Cybozu Garoon en versiones anteriores a 4.2.2 permite a atacantes remotos eludir la autenticación de acceso a través de vectores relacionados con el uso de API. • http://jvn.jp/en/jp/JVN89211736/index.html http://jvndb.jvn.jp/en/contents/2016/JVNDB-2016-000148.html http://www.securityfocus.com/bid/92598 https://support.cybozu.com/ja-jp/article/9408 • CWE-287: Improper Authentication •
CVE-2014-1994
https://notcve.org/view.php?id=CVE-2014-1994
Cross-site scripting (XSS) vulnerability in the Notices portlet in Cybozu Garoon 2.x and 3.x before 3.7 SP4 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. Vulnerabilidad de XSS en el portlet Notices en Cybozu Garoon 2.x y 3.x anterior a 3.7 SP4 permite a usuarios remotos autenticados inyectar secuencias de comandos web o HTML arbitrarios a través de vectores no especificados. • http://cs.cybozu.co.jp/information/gr20140714up04.php http://jvn.jp/en/jp/JVN80583739/index.html http://jvndb.jvn.jp/jvndb/JVNDB-2014-000076 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2014-1995
https://notcve.org/view.php?id=CVE-2014-1995
Cross-site scripting (XSS) vulnerability in the Map search functionality in Cybozu Garoon 2.x and 3.x before 3.7 SP4 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. Vulnerabilidad de XSS en la funcionalidad Map Search en Cybozu Garoon 2.x y 3.x anterior a 3.7 SP4 permite a usuarios remotos autenticados inyectar secuencias de comandos web o HTML arbitrarios a través de vectores no especificados. • http://cs.cybozu.co.jp/information/gr20140714up02.php http://jvn.jp/en/jp/JVN97558950/index.html http://jvndb.jvn.jp/jvndb/JVNDB-2014-000075 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •