4
CVSSv2

CVE-2013-1645

Published: 05/09/2013 Updated: 26/09/2013
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
VMScore: 405
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

Directory traversal vulnerability in Open-Xchange Server prior to 6.20.7 rev14, 6.22.0 before rev13, and 6.22.1 before rev14 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the publication template path.

Vulnerable Product Search on Vulmon Subscribe to Product

open-xchange open-xchange server 6.22.1

open-xchange open-xchange server 6.22.0

open-xchange open-xchange server 6.20.7

Exploits

Multiple security issues for Open-Xchange Server have been discovered and fixed The vendor has chosen responsible full disclosure to publish security issue details Users of the software have already been provided with patched versions Proof regarding authenticity can be obtained from the published release notes: softwareopen-xchangecom ...
Open-Xchange version 6 suffers from cross site scripting, local file inclusion, HTTP header injection / response splitting, missing SSL enforcement, server-side request forging, insecure password hashing, and file permission vulnerabilities ...