CVE-2016-4841
https://notcve.org/view.php?id=CVE-2016-4841
Cybozu Mailwise before 5.4.0 allows remote attackers to inject arbitrary email headers. Cybozu Mailwise en versiones anteriores a 5.4.0 permite a atacantes inyectar las cabeceras de email arbitrarios. • http://jvn.jp/en/jp/JVN01353821/index.html http://jvndb.jvn.jp/en/contents/2016/JVNDB-2016-000135.html http://www.securityfocus.com/bid/92459 https://support.cybozu.com/ja-jp/article/9607 • CWE-20: Improper Input Validation •
CVE-2016-1213
https://notcve.org/view.php?id=CVE-2016-1213
The "Scheduler" function in Cybozu Garoon before 4.2.2 allows remote attackers to redirect users to arbitrary websites. La función "Scheduler" en Cybozu Garoon en versiones anteriores a 4.2.2 permite a atacantes remotos redirigir a los usuarios a sitios web arbitrarios. • http://jvn.jp/en/jp/JVN67266823/index.html http://jvndb.jvn.jp/jvndb/JVNDB-2016-000142 http://www.securityfocus.com/bid/92596 https://support.cybozu.com/ja-jp/article/9221 • CWE-601: URL Redirection to Untrusted Site ('Open Redirect') •
CVE-2016-4844
https://notcve.org/view.php?id=CVE-2016-4844
Cybozu Mailwise before 5.4.0 allows remote attackers to conduct clickjacking attacks. Cybozu Mailwise en versiones anteriores a 5.4.0 permite a atacantes remotos conducir ataques de clickjacking. • http://jvn.jp/en/jp/JVN04125292/index.html http://jvndb.jvn.jp/en/contents/2016/JVNDB-2016-000138.html http://www.securityfocus.com/bid/92462 https://support.cybozu.com/ja-jp/article/9605 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2016-1216
https://notcve.org/view.php?id=CVE-2016-1216
Cross-site scripting (XSS) vulnerability in the "New appointment" function in Cybozu Garoon before 4.2.2. Vulnerabilidad XSS en la función "New appointment" en Cybozu Garoon en versiones anteriores a 4.2.2. • http://jvn.jp/en/jp/JVN67595539/index.html http://jvndb.jvn.jp/en/contents/2016/JVNDB-2016-000145.html http://www.securityfocus.com/bid/92601 https://support.cybozu.com/ja-jp/article/9223 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2016-1218
https://notcve.org/view.php?id=CVE-2016-1218
SQL injection vulnerability in Cybozu Garoon before 4.2.2. Vulnerabilidad de inyección SQL en Cybozu Garoon en versiones anteriores a 4.2.2. • http://jvn.jp/en/jp/JVN83568336/index.html http://jvndb.jvn.jp/en/contents/2016/JVNDB-2016-000147.html http://www.securityfocus.com/bid/92600 https://support.cybozu.com/ja-jp/article/9414 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •