header-logo
Suggest Exploit
vendor:
Open-Xchange Server 6
by:
Open-Xchange GmbH
4,5
CVSS
(AV:L/AC:H/Au:S/C:P/I:P/A:N/E:P/RL:U/RC:C/CDP:LM/TD:H/CR:ND/IR:ND/AR:ND)
Cross Site Scripting
79
CWE
Product Name: Open-Xchange Server 6
Affected Version From: 6.22.1-rev13
Affected Version To: 6.20.7-rev14, 6.22.0-rev13, 6.22.1-rev14
Patch Exists: YES
Related CWE: CVE-2013-1646
CPE: a:open-xchange:open-xchange_server_6
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: None
2013

Multiple security issues for Open-Xchange Server

Since user input is not fully sanitized, carefully crafted content gets returned as JS code which can be used to execute arbitrary JS code at the users context.

Mitigation:

Fixed by Vendor
Source

Exploit-DB raw data: