Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
open-xchange open-xchange server 6.22.1 vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2013-1646
Multiple cross-site scripting (XSS) vulnerabilities in Open-Xchange Server prior to 6.20.7 rev14, 6.22.0 before rev13, and 6.22.1 before rev14 allow remote malicious users to inject arbitrary web script or HTML via (1) invalid JSON data in a mail-sending POST request, (2) an arbi...
Open-xchange Open-xchange Server 6.22.1
Open-xchange Open-xchange Server 6.20.7
Open-xchange Open-xchange Server 6.22.0
1 EDB exploit
NA
CVE-2013-2582
CRLF injection vulnerability in the redirect servlet in Open-Xchange AppSuite and Server prior to 6.22.0 rev15, 6.22.1 before rev17, 7.0.1 before rev6, and 7.0.2 before rev7 allows remote malicious users to inject arbitrary HTTP headers and conduct open redirect attacks by levera...
Open-xchange Open-xchange Appsuite 6.22.1
Open-xchange Open-xchange Server 7.0.2
Open-xchange Open-xchange Appsuite 6.22.0
Open-xchange Open-xchange Server 7.0.1
Open-xchange Open-xchange Appsuite 7.0.1
Open-xchange Open-xchange Server 6.22.1
Open-xchange Open-xchange Appsuite 7.0.2
Open-xchange Open-xchange Server 6.22.0
NA
CVE-2013-2583
Multiple cross-site scripting (XSS) vulnerabilities in Open-Xchange AppSuite and Server prior to 6.20.7 rev16, 6.22.0 before rev15, 6.22.1 before rev17, 7.0.1 before rev6, and 7.0.2 before rev7 allow remote malicious users to inject arbitrary web script or HTML via (1) a javascri...
Open-xchange Open-xchange Appsuite 6.22.1
Open-xchange Open-xchange Server 7.0.2
Open-xchange Open-xchange Appsuite 6.22.0
Open-xchange Open-xchange Server 7.0.1
Open-xchange Open-xchange Appsuite 7.0.1
Open-xchange Open-xchange Server 6.22.1
Open-xchange Open-xchange Appsuite 7.0.2
Open-xchange Open-xchange Server 6.20.7
Open-xchange Open-xchange Appsuite 6.20.7
Open-xchange Open-xchange Server 6.22.0
NA
CVE-2013-5698
Cross-site scripting (XSS) vulnerability in Open-Xchange AppSuite and Server prior to 6.22.0 rev16, 6.22.1 before rev19, 7.0.1 before rev7, 7.0.2 before rev11, and 7.2.0 before rev8 allows remote authenticated users to inject arbitrary web script or HTML via a delivery=view actio...
Open-xchange Open-xchange Appsuite 6.22.1
Open-xchange Open-xchange Server 7.0.2
Open-xchange Open-xchange Appsuite 6.22.0
Open-xchange Open-xchange Server 7.0.1
Open-xchange Open-xchange Appsuite 7.0.1
Open-xchange Open-xchange Server 6.22.1
Open-xchange Open-xchange Appsuite 7.0.2
Open-xchange Open-xchange Appsuite 7.2.0
Open-xchange Open-xchange Server 6.22.0
Open-xchange Open-xchange Server 7.2.0
NA
CVE-2013-1645
Directory traversal vulnerability in Open-Xchange Server prior to 6.20.7 rev14, 6.22.0 before rev13, and 6.22.1 before rev14 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the publication template path.
Open-xchange Open-xchange Server 6.22.1
Open-xchange Open-xchange Server 6.20.7
Open-xchange Open-xchange Server 6.22.0
1 EDB exploit
NA
CVE-2013-1647
Multiple CRLF injection vulnerabilities in Open-Xchange Server prior to 6.20.7 rev14, 6.22.0 before rev13, and 6.22.1 before rev14 allow remote malicious users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted parameter, as demonstrated by...
Open-xchange Open-xchange Server 6.22.1
Open-xchange Open-xchange Server 6.20.7
Open-xchange Open-xchange Server 6.22.0
1 EDB exploit
NA
CVE-2013-1648
The Subscriptions feature in Open-Xchange Server prior to 6.20.7 rev14, 6.22.0 before rev13, and 6.22.1 before rev14 does not properly validate the publication-source URL, which allows remote authenticated users to trigger arbitrary outbound TCP traffic via a crafted Source field...
Open-xchange Open-xchange Server 6.22.1
Open-xchange Open-xchange Server 6.20.7
Open-xchange Open-xchange Server 6.22.0
1 EDB exploit
NA
CVE-2013-1650
Open-Xchange Server prior to 6.20.7 rev14, 6.22.0 before rev13, and 6.22.1 before rev14 uses weak permissions (group "other" readable) under opt/open-xchange/etc/, which allows local users to obtain sensitive information via standard filesystem operations.
Open-xchange Open-xchange Server 6.22.1
Open-xchange Open-xchange Server 6.20.7
Open-xchange Open-xchange Server 6.22.0
1 EDB exploit
NA
CVE-2013-1649
Open-Xchange Server prior to 6.20.7 rev14, 6.22.0 before rev13, and 6.22.1 before rev14 uses the crypt and SHA-1 algorithms for password hashing, which makes it easier for context-dependent malicious users to obtain cleartext passwords via a brute-force attack.
Open-xchange Open-xchange Server 6.22.1
Open-xchange Open-xchange Server 6.20.7
Open-xchange Open-xchange Server 6.22.0
1 EDB exploit
NA
CVE-2013-1651
OXUpdater in Open-Xchange Server prior to 6.20.7 rev14, 6.22.0 before rev13, and 6.22.1 before rev14 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle malicious users to spoof update servers and install arbitrary software via a crafted certificat...
Open-xchange Open-xchange Server 6.22.1
Open-xchange Open-xchange Server 6.20.7
Open-xchange Open-xchange Server 6.22.0
1 EDB exploit
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
SSRF
server-side request forgery
CVE-2024-30067
CVE-2024-5553
CVE-2024-30095
IDOR
CVE-2024-35252
CVE-2024-23692
CVE-2024-27801
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »