Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
open-xchange open-xchange appsuite 7.2.0 vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2013-6009
CRLF injection vulnerability in Open-Xchange AppSuite prior to 7.2.2, when using AJP in certain conditions, allows remote malicious users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the ajax/defer servlet.
Open-xchange Open-xchange Appsuite
Open-xchange Open-xchange Appsuite 7.2.0
Open-xchange Open-xchange Appsuite 6.20.7
Open-xchange Open-xchange Appsuite 7.0.1
Open-xchange Open-xchange Appsuite 6.22.0
Open-xchange Open-xchange Appsuite 7.0.2
Open-xchange Open-xchange Appsuite 6.22.1
NA
CVE-2013-5690
Multiple cross-site scripting (XSS) vulnerabilities in Open-Xchange AppSuite prior to 7.2.2 allow remote authenticated users to inject arbitrary web script or HTML via (1) content with the text/xml MIME type or (2) the Status comment field of an appointment.
Open-xchange Open-xchange Appsuite 6.20.7
Open-xchange Open-xchange Appsuite 7.0.1
Open-xchange Open-xchange Appsuite 6.22.0
Open-xchange Open-xchange Appsuite
Open-xchange Open-xchange Appsuite 7.2.0
Open-xchange Open-xchange Appsuite 7.0.2
Open-xchange Open-xchange Appsuite 6.22.1
NA
CVE-2013-7140
XML External Entity (XXE) vulnerability in the CalDAV interface in Open-Xchange (OX) AppSuite 7.4.1 and previous versions allows remote authenticated users to read portions of arbitrary files via vectors related to the SAX builder and the WebDAV interface. NOTE: this issue has be...
Open-xchange Open-xchange Appsuite 7.2.0
Open-xchange Open-xchange Appsuite 7.0.2
Open-xchange Open-xchange Appsuite 7.2.2
Open-xchange Open-xchange Appsuite 7.2.1
Open-xchange Open-xchange Appsuite
Open-xchange Open-xchange Appsuite 7.4.0
Open-xchange Open-xchange Appsuite 6.22.0
Open-xchange Open-xchange Appsuite 6.20.7
Open-xchange Open-xchange Appsuite 7.0.1
Open-xchange Open-xchange Appsuite 6.22.1
NA
CVE-2013-7141
Cross-site scripting (XSS) vulnerability in Open-Xchange (OX) AppSuite 7.4.1 and previous versions allows remote malicious users to inject arbitrary web script or HTML via unspecified vectors related to crafted "<%" tags.
Open-xchange Open-xchange Appsuite 7.2.2
Open-xchange Open-xchange Appsuite 7.2.1
Open-xchange Open-xchange Appsuite
Open-xchange Open-xchange Appsuite 7.2.0
Open-xchange Open-xchange Appsuite 7.0.2
Open-xchange Open-xchange Appsuite 7.0.1
Open-xchange Open-xchange Appsuite 6.22.1
Open-xchange Open-xchange Appsuite 7.4.0
Open-xchange Open-xchange Appsuite 6.22.0
Open-xchange Open-xchange Appsuite 6.20.7
NA
CVE-2013-7142
Cross-site scripting (XSS) vulnerability in Open-Xchange (OX) AppSuite 7.4.1 and previous versions allows remote malicious users to inject arbitrary web script or HTML via unspecified oAuth API functions.
Open-xchange Open-xchange Appsuite 7.4.0
Open-xchange Open-xchange Appsuite 7.0.2
Open-xchange Open-xchange Appsuite 7.0.1
Open-xchange Open-xchange Appsuite 6.22.1
Open-xchange Open-xchange Appsuite 6.22.0
Open-xchange Open-xchange Appsuite 7.2.2
Open-xchange Open-xchange Appsuite 6.20.7
Open-xchange Open-xchange Appsuite
Open-xchange Open-xchange Appsuite 7.2.1
Open-xchange Open-xchange Appsuite 7.2.0
NA
CVE-2013-7143
Cross-site scripting (XSS) vulnerability in Open-Xchange (OX) AppSuite 7.4.1 allows remote malicious users to inject arbitrary web script or HTML via the title in a mail filter rule.
Open-xchange Open-xchange Appsuite 7.2.1
Open-xchange Open-xchange Appsuite 7.2.0
Open-xchange Open-xchange Appsuite 6.22.1
Open-xchange Open-xchange Appsuite 6.22.0
Open-xchange Open-xchange Appsuite 6.20.7
Open-xchange Open-xchange Appsuite 7.4.0
Open-xchange Open-xchange Appsuite 7.2.2
Open-xchange Open-xchange Appsuite
Open-xchange Open-xchange Appsuite 7.0.2
Open-xchange Open-xchange Appsuite 7.0.1
NA
CVE-2013-6997
Multiple cross-site scripting (XSS) vulnerabilities in Open-Xchange (OX) AppSuite 7.4.0 and previous versions allow remote malicious users to inject arbitrary web script or HTML via (1) an HTML email with crafted CSS code containing wildcards or (2) office documents containing &q...
Open-xchange Open-xchange Appsuite 6.20.7
Open-xchange Open-xchange Appsuite 6.22.0
Open-xchange Open-xchange Appsuite
Open-xchange Open-xchange Appsuite 7.0.2
Open-xchange Open-xchange Appsuite 7.2.0
Open-xchange Open-xchange Appsuite 6.22.1
Open-xchange Open-xchange Appsuite 7.0.1
Open-xchange Open-xchange Appsuite 7.2.1
Open-xchange Open-xchange Appsuite 7.2.2
NA
CVE-2013-5698
Cross-site scripting (XSS) vulnerability in Open-Xchange AppSuite and Server prior to 6.22.0 rev16, 6.22.1 before rev19, 7.0.1 before rev7, 7.0.2 before rev11, and 7.2.0 before rev8 allows remote authenticated users to inject arbitrary web script or HTML via a delivery=view actio...
Open-xchange Open-xchange Appsuite 7.0.1
Open-xchange Open-xchange Appsuite 7.0.2
Open-xchange Open-xchange Server 7.0.1
Open-xchange Open-xchange Server 7.0.2
Open-xchange Open-xchange Server 6.22.0
Open-xchange Open-xchange Appsuite 6.22.0
Open-xchange Open-xchange Server 7.2.0
Open-xchange Open-xchange Server 6.22.1
Open-xchange Open-xchange Appsuite 6.22.1
Open-xchange Open-xchange Appsuite 7.2.0
NA
CVE-2014-5235
Cross-site scripting (XSS) vulnerability in the frontend in Open-Xchange (OX) AppSuite prior to 7.4.2-rev33 and 7.6.x prior to 7.6.0-rev16 allows remote malicious users to inject arbitrary web script or HTML via vectors related to unspecified fields in RSS feeds.
Open-xchange Open-xchange Appsuite 6.22.0
Open-xchange Open-xchange Appsuite 6.22.1
Open-xchange Open-xchange Appsuite 7.6.0
Open-xchange Open-xchange Appsuite 7.2.0
Open-xchange Open-xchange Appsuite 7.2.1
Open-xchange Open-xchange Appsuite 6.20.7
Open-xchange Open-xchange Appsuite 7.2.2
Open-xchange Open-xchange Appsuite 7.4.0
Open-xchange Open-xchange Appsuite
Open-xchange Open-xchange Appsuite 7.0.1
Open-xchange Open-xchange Appsuite 7.0.2
NA
CVE-2014-5234
Cross-site scripting (XSS) vulnerability in the backend in Open-Xchange (OX) AppSuite prior to 7.4.2-rev33 and 7.6.x prior to 7.6.0-rev16 allows remote malicious users to inject arbitrary web script or HTML via a folder publication name.
Open-xchange Open-xchange Appsuite 7.2.0
Open-xchange Open-xchange Appsuite 7.2.1
Open-xchange Open-xchange Appsuite 6.22.0
Open-xchange Open-xchange Appsuite 6.22.1
Open-xchange Open-xchange Appsuite
Open-xchange Open-xchange Appsuite 7.6.0
Open-xchange Open-xchange Appsuite 7.0.1
Open-xchange Open-xchange Appsuite 7.0.2
Open-xchange Open-xchange Appsuite 6.20.7
Open-xchange Open-xchange Appsuite 7.2.2
Open-xchange Open-xchange Appsuite 7.4.0
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-52710
arbitrary
CVE-2024-5272
CVE-2024-2961
brute force
remote
CVE-2024-32944
CVE-2024-36241
CVE-2024-5274
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
NEXT »