Page 4 of 70 results (0.004 seconds)

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 0

20 Apr 2017 — Cross-site scripting (XSS) vulnerability in the "Check available times" function in Cybozu Garoon before 4.2.2. Vulnerabilidad XSS en la función "Check available times" en Cybozu Garoon en versiones anteriores a 4.2.2. • http://jvn.jp/en/jp/JVN67595539/index.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 0

20 Apr 2017 — Cross-site scripting (XSS) vulnerability in the "User details" function in Cybozu Garoon before 4.2.2. Vulnerabilidad XSS en la función "User details" en Cybozu Garoon en versiones anteriores a 4.2.2. • http://jvn.jp/en/jp/JVN67595539/index.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 0

20 Apr 2017 — Cross-site scripting (XSS) vulnerability in the "New appointment" function in Cybozu Garoon before 4.2.2. Vulnerabilidad XSS en la función "New appointment" en Cybozu Garoon en versiones anteriores a 4.2.2. • http://jvn.jp/en/jp/JVN67595539/index.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 0

20 Apr 2017 — The "Scheduler" function in Cybozu Garoon before 4.2.2 allows remote attackers to redirect users to arbitrary websites. La función "Scheduler" en Cybozu Garoon en versiones anteriores a 4.2.2 permite a atacantes remotos redirigir a los usuarios a sitios web arbitrarios. • http://jvn.jp/en/jp/JVN67266823/index.html • CWE-601: URL Redirection to Untrusted Site ('Open Redirect') •

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 0

20 Apr 2017 — Cross-site scripting (XSS) vulnerability in the "Response request" function in Cybozu Garoon before 4.2.2. Vulnerabilidad XSS en la función "Response request" en Cybozu Garoon en versiones anteriores a 4.2.2. • http://jvn.jp/en/jp/JVN67595539/index.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 9.8EPSS: 3%CPEs: 1EXPL: 0

20 Apr 2017 — Cybozu Garoon before 4.2.2 allows remote attackers to bypass login authentication via vectors related to API use. Cybozu Garoon en versiones anteriores a 4.2.2 permite a atacantes remotos eludir la autenticación de acceso a través de vectores relacionados con el uso de API. • http://jvn.jp/en/jp/JVN89211736/index.html • CWE-287: Improper Authentication •

CVSS: 6.5EPSS: 0%CPEs: 21EXPL: 0

25 Jun 2016 — Cybozu Garoon 3.1 through 4.2 allows remote authenticated users to bypass intended restrictions on MultiReport reading via unspecified vectors. Cybozu Garoon 3.1 hasta la versión 4.2 permite a usuarios remotos autenticados eludir las restricciones destinadas a la lectura de MultiReport a través de vectores no especificados. • http://jvn.jp/en/jp/JVN18975349/index.html • CWE-284: Improper Access Control •

CVSS: 8.1EPSS: 0%CPEs: 21EXPL: 0

25 Jun 2016 — Cybozu Garoon 3.x and 4.x before 4.2.1 allows remote authenticated users to bypass intended restrictions on reading, creating, or modifying a portlet via unspecified vectors. Cybozu Garoon 3.x y 4.x en versiones anteriores a 4.2.1 permite a usuarios remotos autenticados eludir las restricciones destinadas a la lectura, creación o modificación de un portlet a través de vectores no especificados. • http://jvn.jp/en/jp/JVN18975349/index.html •

CVSS: 6.5EPSS: 0%CPEs: 21EXPL: 0

25 Jun 2016 — Cybozu Garoon 3.x and 4.x before 4.2.1 allows remote authenticated users to send spoofed e-mail messages via unspecified vectors. Cybozu Garoon 3.x y 4.x en versiones anteriores a 4.2.1 permite a usuarios remotos autenticados enviar mensajes de correo electrónico suplantados a través de vectores no especificados. • http://jvn.jp/en/jp/JVN18975349/index.html •

CVSS: 5.3EPSS: 0%CPEs: 25EXPL: 0

19 Jun 2016 — Directory traversal vulnerability in the Files function in Cybozu Garoon 3.x and 4.x before 4.2.1 allows remote attackers to modify settings via unspecified vectors. Vulnerabilidad de salto de directorio en la función Files en Cybozu Garoon 3.x y 4.x en versiones anteriores a 4.2.1 permite a atacantes remotos modificar ajustes a través de vectores no especificados. • http://jvn.jp/en/jp/JVN14749391/index.html • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •