Page 8 of 49 results (0.006 seconds)

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 0

Cross-site scripting (XSS) vulnerability in the "Response request" function in Cybozu Garoon before 4.2.2. Vulnerabilidad XSS en la función "Response request" en Cybozu Garoon en versiones anteriores a 4.2.2. • http://jvn.jp/en/jp/JVN67595539/index.html http://jvndb.jvn.jp/en/contents/2016/JVNDB-2016-000143.html http://www.securityfocus.com/bid/92601 https://support.cybozu.com/ja-jp/article/9222 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 9.8EPSS: 0%CPEs: 1EXPL: 0

Cybozu Garoon before 4.2.2 allows remote attackers to bypass login authentication via vectors related to API use. Cybozu Garoon en versiones anteriores a 4.2.2 permite a atacantes remotos eludir la autenticación de acceso a través de vectores relacionados con el uso de API. • http://jvn.jp/en/jp/JVN89211736/index.html http://jvndb.jvn.jp/en/contents/2016/JVNDB-2016-000148.html http://www.securityfocus.com/bid/92598 https://support.cybozu.com/ja-jp/article/9408 • CWE-287: Improper Authentication •

CVSS: 7.5EPSS: 0%CPEs: 11EXPL: 0

Cybozu Garoon 3.7 through 4.2 allows remote attackers to obtain sensitive email-reading information via unspecified vectors. Cybozu Garoon 3.7 hasta la versión 4.2 permite a atacantes remotos obtener información sensible de la lectura de correo electrónico a través de vectores no especificados. • http://jvn.jp/en/jp/JVN25765762/index.html http://jvndb.jvn.jp/jvndb/JVNDB-2016-000079 https://support.cybozu.com/ja-jp/article/8919 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVSS: 8.1EPSS: 0%CPEs: 21EXPL: 0

Cybozu Garoon 3.x and 4.x before 4.2.1 allows remote authenticated users to bypass intended restrictions on reading, creating, or modifying a portlet via unspecified vectors. Cybozu Garoon 3.x y 4.x en versiones anteriores a 4.2.1 permite a usuarios remotos autenticados eludir las restricciones destinadas a la lectura, creación o modificación de un portlet a través de vectores no especificados. • http://jvn.jp/en/jp/JVN18975349/index.html http://jvndb.jvn.jp/jvndb/JVNDB-2016-000093 https://garoon.cybozu.co.jp/support/update/package/421sp1.html#03 https://support.cybozu.com/ja-jp/article/9020 •

CVSS: 6.5EPSS: 0%CPEs: 21EXPL: 0

Cybozu Garoon 3.x and 4.x before 4.2.1 allows remote authenticated users to send spoofed e-mail messages via unspecified vectors. Cybozu Garoon 3.x y 4.x en versiones anteriores a 4.2.1 permite a usuarios remotos autenticados enviar mensajes de correo electrónico suplantados a través de vectores no especificados. • http://jvn.jp/en/jp/JVN18975349/index.html http://jvndb.jvn.jp/jvndb/JVNDB-2016-000077 https://garoon.cybozu.co.jp/support/update/package/421sp1.html#03 https://support.cybozu.com/ja-jp/article/8845 •