2.1
CVSSv2

CVE-2013-1650

Published: 05/09/2013 Updated: 26/09/2013
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
VMScore: 215
Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Open-Xchange Server prior to 6.20.7 rev14, 6.22.0 before rev13, and 6.22.1 before rev14 uses weak permissions (group "other" readable) under opt/open-xchange/etc/, which allows local users to obtain sensitive information via standard filesystem operations.

Vulnerable Product Search on Vulmon Subscribe to Product

open-xchange open-xchange server 6.22.1

open-xchange open-xchange server 6.20.7

open-xchange open-xchange server 6.22.0

Exploits

Multiple security issues for Open-Xchange Server have been discovered and fixed The vendor has chosen responsible full disclosure to publish security issue details Users of the software have already been provided with patched versions Proof regarding authenticity can be obtained from the published release notes: softwareopen-xchangecom ...
Open-Xchange version 6 suffers from cross site scripting, local file inclusion, HTTP header injection / response splitting, missing SSL enforcement, server-side request forging, insecure password hashing, and file permission vulnerabilities ...