Vulnerabilities > Open Xchange

DATE CVE VULNERABILITY TITLE RISK
2013-09-05 CVE-2013-1649 Credentials Management vulnerability in Open-Xchange Server 6.20.7/6.22.0/6.22.1
Open-Xchange Server before 6.20.7 rev14, 6.22.0 before rev13, and 6.22.1 before rev14 uses the crypt and SHA-1 algorithms for password hashing, which makes it easier for context-dependent attackers to obtain cleartext passwords via a brute-force attack.
4.3
2013-09-05 CVE-2013-1648 Improper Input Validation vulnerability in Open-Xchange Server 6.20.7/6.22.0/6.22.1
The Subscriptions feature in Open-Xchange Server before 6.20.7 rev14, 6.22.0 before rev13, and 6.22.1 before rev14 does not properly validate the publication-source URL, which allows remote authenticated users to trigger arbitrary outbound TCP traffic via a crafted Source field, as demonstrated by (1) an ftp: URL, (2) a gopher: URL, or (3) an http://127.0.0.1/ URL, related to a "Server-side request forging (SSRF)" issue.
3.5
2013-09-05 CVE-2013-1647 Code Injection vulnerability in Open-Xchange Server 6.20.7/6.22.0/6.22.1
Multiple CRLF injection vulnerabilities in Open-Xchange Server before 6.20.7 rev14, 6.22.0 before rev13, and 6.22.1 before rev14 allow remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted parameter, as demonstrated by (1) the location parameter to ajax/redirect or (2) multiple infostore URIs.
network
low complexity
open-xchange CWE-94
5.0
2013-09-05 CVE-2013-1646 Cross-Site Scripting vulnerability in Open-Xchange Server 6.20.7/6.22.0/6.22.1
Multiple cross-site scripting (XSS) vulnerabilities in Open-Xchange Server before 6.20.7 rev14, 6.22.0 before rev13, and 6.22.1 before rev14 allow remote attackers to inject arbitrary web script or HTML via (1) invalid JSON data in a mail-sending POST request, (2) an arbitrary parameter to servlet/TestServlet, (3) a javascript: URL in a standalone-mode action to a UWA module, (4) an infostore attachment, (5) JavaScript code in a contact image, (6) an RSS feed, or (7) a signature.
4.3
2013-09-05 CVE-2013-1645 Path Traversal vulnerability in Open-Xchange Server 6.20.7/6.22.0/6.22.1
Directory traversal vulnerability in Open-Xchange Server before 6.20.7 rev14, 6.22.0 before rev13, and 6.22.1 before rev14 allows remote authenticated users to read arbitrary files via a ..
network
low complexity
open-xchange CWE-22
4.0
2006-06-01 CVE-2006-2738 Unspecified vulnerability in Open-Xchange 0.8.1.6
The open source version of Open-Xchange 0.8.2 and earlier uses a static default username and password with a valid login shell in the initfile for the ldap-server, which allows remote attackers to access any server where the default has not been changed.
network
low complexity
open-xchange
7.5
2006-01-05 CVE-2006-0091 Cross-Site Scripting vulnerability in Open-Xchange
Cross-site scripting (XSS) vulnerability in webmail in Open-Xchange 0.8.1-6 and earlier, with "Inline HTML" enabled, allows remote attackers to inject arbitrary web script or HTML via e-mail attachments, which are rendered inline.
network
open-xchange
4.3