Vulnerabilities > CVE-2013-4790 - Credentials Management vulnerability in Open-Xchange Appsuite
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Open-Xchange AppSuite before 7.0.2 rev14, 7.2.0 before rev11, 7.2.1 before rev10, and 7.2.2 before rev9 relies on user-supplied data to predict the IMAP server hostname for an external domain name, which allows remote authenticated users to discover e-mail credentials of other users in opportunistic circumstances via a manual-mode association of a personal e-mail address with the hostname of a crafted IMAP server.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 4 |
Common Weakness Enumeration (CWE)
Packetstorm
data source | https://packetstormsecurity.com/files/download/122635/openxchange-inject.txt |
id | PACKETSTORM:122635 |
last seen | 2016-12-05 |
published | 2013-08-01 |
reporter | Martin Braun |
source | https://packetstormsecurity.com/files/122635/Open-Xchange-AppSuite-7.2.2-Phishing-Data-Injection.html |
title | Open-Xchange AppSuite 7.2.2 Phishing / Data Injection |