CVE-2016-1196
https://notcve.org/view.php?id=CVE-2016-1196
Cybozu Garoon 3.x and 4.x before 4.2.1 allows remote authenticated users to bypass intended access restrictions and obtain sensitive Address Book information via an API call, a different vulnerability than CVE-2015-7776. Cybozu Garoon 3.x y 4.x en versiones anteriores a 4.2.1 permite a usuarios remotos autenticados eludir restricciones destinadas al acceso y obtener información sensible de Address Book a través de una llamada API, una vulnerabilidad diferente a CVE-2015-7776. • http://jvn.jp/en/jp/JVN33879831/index.html http://jvndb.jvn.jp/jvndb/JVNDB-2016-000082 https://support.cybozu.com/ja-jp/article/8970 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-264: Permissions, Privileges, and Access Controls •
CVE-2016-1197
https://notcve.org/view.php?id=CVE-2016-1197
Cross-site scripting (XSS) vulnerability in Cybozu Garoon 4.x before 4.2.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2015-7775. Vulnerabilidad de XSS en Cybozu Garoon 4.x en versiones anteriores a 4.2.1 permite a atacantes remotos inyectar secuencias de comandos web o HTML manipulados a través de vectores no especificados, una vulnerabilidad diferente a CVE-2015-7775. • http://jvn.jp/en/jp/JVN37121456/index.html http://jvndb.jvn.jp/jvndb/JVNDB-2016-000083 https://support.cybozu.com/ja-jp/article/9303 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2016-1195
https://notcve.org/view.php?id=CVE-2016-1195
Open redirect vulnerability in Cybozu Garoon 3.x and 4.x before 4.2.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL. Vulnerabilidad de redirección abierta en Cybozu Garoon 3.x y 4.x en versiones anteriores a 4.2.1 permite a atacantes remotos redirigir usuarios a sitios web arbitrarios y llevar a cabo ataques de phishing a través de una URL manipulada. • http://jvn.jp/en/jp/JVN32218514/index.html http://jvndb.jvn.jp/jvndb/JVNDB-2016-000081 https://support.cybozu.com/ja-jp/article/8987 •