CVE-2013-2582
 
Severity Score
6.1
*CVSS v3
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
CRLF injection vulnerability in the redirect servlet in Open-Xchange AppSuite and Server before 6.22.0 rev15, 6.22.1 before rev17, 7.0.1 before rev6, and 7.0.2 before rev7 allows remote attackers to inject arbitrary HTTP headers and conduct open redirect attacks by leveraging improper sanitization of whitespace characters.
Vulnerabilidad de inyección CRLF en el servlet para redirigir en Open-Xchange AppSuite y Server anterior a v6.22.0 rev15, v6.22.1 anterior a rev17, v7.0.1 anterior a rev6, y v7.0.2 anterior a rev7 permite a atacantes remotos inyectar cabeceras HTTP arbitrarias y llevar a cabo ataques de redirección abierta mediante el aprovechamiento de saneamiento inadecuado de espacios en blanco.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2013-03-15 CVE Reserved
- 2013-04-17 CVE Published
- 2024-09-16 CVE Updated
- 2024-09-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-94: Improper Control of Generation of Code ('Code Injection')
CAPEC
References (1)
URL | Tag | Source |
---|---|---|
http://archives.neohapsis.com/archives/bugtraq/2013-04/0183.html | Mailing List |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Open-xchange Search vendor "Open-xchange" | Open-xchange Appsuite Search vendor "Open-xchange" for product "Open-xchange Appsuite" | 6.22.0 Search vendor "Open-xchange" for product "Open-xchange Appsuite" and version "6.22.0" | - |
Affected
| ||||||
Open-xchange Search vendor "Open-xchange" | Open-xchange Appsuite Search vendor "Open-xchange" for product "Open-xchange Appsuite" | 6.22.1 Search vendor "Open-xchange" for product "Open-xchange Appsuite" and version "6.22.1" | - |
Affected
| ||||||
Open-xchange Search vendor "Open-xchange" | Open-xchange Appsuite Search vendor "Open-xchange" for product "Open-xchange Appsuite" | 7.0.1 Search vendor "Open-xchange" for product "Open-xchange Appsuite" and version "7.0.1" | - |
Affected
| ||||||
Open-xchange Search vendor "Open-xchange" | Open-xchange Appsuite Search vendor "Open-xchange" for product "Open-xchange Appsuite" | 7.0.2 Search vendor "Open-xchange" for product "Open-xchange Appsuite" and version "7.0.2" | - |
Affected
| ||||||
Open-xchange Search vendor "Open-xchange" | Open-xchange Server Search vendor "Open-xchange" for product "Open-xchange Server" | 6.22.0 Search vendor "Open-xchange" for product "Open-xchange Server" and version "6.22.0" | - |
Affected
| ||||||
Open-xchange Search vendor "Open-xchange" | Open-xchange Server Search vendor "Open-xchange" for product "Open-xchange Server" | 6.22.1 Search vendor "Open-xchange" for product "Open-xchange Server" and version "6.22.1" | - |
Affected
| ||||||
Open-xchange Search vendor "Open-xchange" | Open-xchange Server Search vendor "Open-xchange" for product "Open-xchange Server" | 7.0.1 Search vendor "Open-xchange" for product "Open-xchange Server" and version "7.0.1" | - |
Affected
| ||||||
Open-xchange Search vendor "Open-xchange" | Open-xchange Server Search vendor "Open-xchange" for product "Open-xchange Server" | 7.0.2 Search vendor "Open-xchange" for product "Open-xchange Server" and version "7.0.2" | - |
Affected
|