
CVE-2016-1214
https://notcve.org/view.php?id=CVE-2016-1214
20 Apr 2017 — Cross-site scripting (XSS) vulnerability in the "Response request" function in Cybozu Garoon before 4.2.2. Vulnerabilidad XSS en la función "Response request" en Cybozu Garoon en versiones anteriores a 4.2.2. • http://jvn.jp/en/jp/JVN67595539/index.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2016-1215
https://notcve.org/view.php?id=CVE-2016-1215
20 Apr 2017 — Cross-site scripting (XSS) vulnerability in the "User details" function in Cybozu Garoon before 4.2.2. Vulnerabilidad XSS en la función "User details" en Cybozu Garoon en versiones anteriores a 4.2.2. • http://jvn.jp/en/jp/JVN67595539/index.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2016-1216
https://notcve.org/view.php?id=CVE-2016-1216
20 Apr 2017 — Cross-site scripting (XSS) vulnerability in the "New appointment" function in Cybozu Garoon before 4.2.2. Vulnerabilidad XSS en la función "New appointment" en Cybozu Garoon en versiones anteriores a 4.2.2. • http://jvn.jp/en/jp/JVN67595539/index.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2016-1217
https://notcve.org/view.php?id=CVE-2016-1217
20 Apr 2017 — Cross-site scripting (XSS) vulnerability in the "Check available times" function in Cybozu Garoon before 4.2.2. Vulnerabilidad XSS en la función "Check available times" en Cybozu Garoon en versiones anteriores a 4.2.2. • http://jvn.jp/en/jp/JVN67595539/index.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2016-1218
https://notcve.org/view.php?id=CVE-2016-1218
20 Apr 2017 — SQL injection vulnerability in Cybozu Garoon before 4.2.2. Vulnerabilidad de inyección SQL en Cybozu Garoon en versiones anteriores a 4.2.2. • http://jvn.jp/en/jp/JVN83568336/index.html • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2016-1220
https://notcve.org/view.php?id=CVE-2016-1220
20 Apr 2017 — Cybozu Garoon before 4.2.2 does not properly restrict access. Cybozu Garoon en versiones anteriores a 4.2.2 no restringe correctamente el acceso. • http://jvn.jp/en/jp/JVN93411577/index.html • CWE-284: Improper Access Control •

CVE-2016-1219
https://notcve.org/view.php?id=CVE-2016-1219
20 Apr 2017 — Cybozu Garoon before 4.2.2 allows remote attackers to bypass login authentication via vectors related to API use. Cybozu Garoon en versiones anteriores a 4.2.2 permite a atacantes remotos eludir la autenticación de acceso a través de vectores relacionados con el uso de API. • http://jvn.jp/en/jp/JVN89211736/index.html • CWE-287: Improper Authentication •

CVE-2016-1188
https://notcve.org/view.php?id=CVE-2016-1188
25 Jun 2016 — Cybozu Garoon 3.x and 4.x before 4.2.1 allows remote authenticated users to send spoofed e-mail messages via unspecified vectors. Cybozu Garoon 3.x y 4.x en versiones anteriores a 4.2.1 permite a usuarios remotos autenticados enviar mensajes de correo electrónico suplantados a través de vectores no especificados. • http://jvn.jp/en/jp/JVN18975349/index.html •

CVE-2016-1189
https://notcve.org/view.php?id=CVE-2016-1189
25 Jun 2016 — Cybozu Garoon 3.x and 4.x before 4.2.1 allows remote authenticated users to bypass intended restrictions on reading, creating, or modifying a portlet via unspecified vectors. Cybozu Garoon 3.x y 4.x en versiones anteriores a 4.2.1 permite a usuarios remotos autenticados eludir las restricciones destinadas a la lectura, creación o modificación de un portlet a través de vectores no especificados. • http://jvn.jp/en/jp/JVN18975349/index.html •

CVE-2016-1190
https://notcve.org/view.php?id=CVE-2016-1190
25 Jun 2016 — Cybozu Garoon 3.1 through 4.2 allows remote authenticated users to bypass intended restrictions on MultiReport reading via unspecified vectors. Cybozu Garoon 3.1 hasta la versión 4.2 permite a usuarios remotos autenticados eludir las restricciones destinadas a la lectura de MultiReport a través de vectores no especificados. • http://jvn.jp/en/jp/JVN18975349/index.html • CWE-284: Improper Access Control •