Vulnerabilities > Open Xchange
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2013-09-05 | CVE-2013-1649 | Credentials Management vulnerability in Open-Xchange Server 6.20.7/6.22.0/6.22.1 Open-Xchange Server before 6.20.7 rev14, 6.22.0 before rev13, and 6.22.1 before rev14 uses the crypt and SHA-1 algorithms for password hashing, which makes it easier for context-dependent attackers to obtain cleartext passwords via a brute-force attack. | 4.3 |
2013-09-05 | CVE-2013-1648 | Improper Input Validation vulnerability in Open-Xchange Server 6.20.7/6.22.0/6.22.1 The Subscriptions feature in Open-Xchange Server before 6.20.7 rev14, 6.22.0 before rev13, and 6.22.1 before rev14 does not properly validate the publication-source URL, which allows remote authenticated users to trigger arbitrary outbound TCP traffic via a crafted Source field, as demonstrated by (1) an ftp: URL, (2) a gopher: URL, or (3) an http://127.0.0.1/ URL, related to a "Server-side request forging (SSRF)" issue. | 3.5 |
2013-09-05 | CVE-2013-1647 | Code Injection vulnerability in Open-Xchange Server 6.20.7/6.22.0/6.22.1 Multiple CRLF injection vulnerabilities in Open-Xchange Server before 6.20.7 rev14, 6.22.0 before rev13, and 6.22.1 before rev14 allow remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted parameter, as demonstrated by (1) the location parameter to ajax/redirect or (2) multiple infostore URIs. | 5.0 |
2013-09-05 | CVE-2013-1646 | Cross-Site Scripting vulnerability in Open-Xchange Server 6.20.7/6.22.0/6.22.1 Multiple cross-site scripting (XSS) vulnerabilities in Open-Xchange Server before 6.20.7 rev14, 6.22.0 before rev13, and 6.22.1 before rev14 allow remote attackers to inject arbitrary web script or HTML via (1) invalid JSON data in a mail-sending POST request, (2) an arbitrary parameter to servlet/TestServlet, (3) a javascript: URL in a standalone-mode action to a UWA module, (4) an infostore attachment, (5) JavaScript code in a contact image, (6) an RSS feed, or (7) a signature. | 4.3 |
2013-09-05 | CVE-2013-1645 | Path Traversal vulnerability in Open-Xchange Server 6.20.7/6.22.0/6.22.1 Directory traversal vulnerability in Open-Xchange Server before 6.20.7 rev14, 6.22.0 before rev13, and 6.22.1 before rev14 allows remote authenticated users to read arbitrary files via a .. | 4.0 |
2006-06-01 | CVE-2006-2738 | Unspecified vulnerability in Open-Xchange 0.8.1.6 The open source version of Open-Xchange 0.8.2 and earlier uses a static default username and password with a valid login shell in the initfile for the ldap-server, which allows remote attackers to access any server where the default has not been changed. | 7.5 |
2006-01-05 | CVE-2006-0091 | Cross-Site Scripting vulnerability in Open-Xchange Cross-site scripting (XSS) vulnerability in webmail in Open-Xchange 0.8.1-6 and earlier, with "Inline HTML" enabled, allows remote attackers to inject arbitrary web script or HTML via e-mail attachments, which are rendered inline. network open-xchange | 4.3 |