|
269391
|
4.3 |
MEDIUM
Network
|
cybozu
|
garoon
|
Cybozu Garoon before 4.2.2 does not properly restrict access.
|
CWE-284
Improper Access Control
|
CVE-2016-1220
|
2024-11-21 11:45 |
2017-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269392
|
8.8 |
HIGH
Network
|
cybozu
|
garoon
|
SQL injection vulnerability in Cybozu Garoon before 4.2.2.
|
CWE-89
SQL Injection
|
CVE-2016-1218
|
2024-11-21 11:45 |
2017-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269393
|
6.1 |
MEDIUM
Network
|
cybozu
|
garoon
|
Cross-site scripting (XSS) vulnerability in the "Check available times" function in Cybozu Garoon before 4.2.2.
|
CWE-79
Cross-site Scripting
|
CVE-2016-1217
|
2024-11-21 11:45 |
2017-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269394
|
6.1 |
MEDIUM
Network
|
cybozu
|
garoon
|
Cross-site scripting (XSS) vulnerability in the "New appointment" function in Cybozu Garoon before 4.2.2.
|
CWE-79
Cross-site Scripting
|
CVE-2016-1216
|
2024-11-21 11:45 |
2017-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269395
|
6.1 |
MEDIUM
Network
|
cybozu
|
garoon
|
Cross-site scripting (XSS) vulnerability in the "User details" function in Cybozu Garoon before 4.2.2.
|
CWE-79
Cross-site Scripting
|
CVE-2016-1215
|
2024-11-21 11:45 |
2017-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269396
|
6.1 |
MEDIUM
Network
|
cybozu
|
garoon
|
Cross-site scripting (XSS) vulnerability in the "Response request" function in Cybozu Garoon before 4.2.2.
|
CWE-79
Cross-site Scripting
|
CVE-2016-1214
|
2024-11-21 11:45 |
2017-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269397
|
6.1 |
MEDIUM
Network
|
cybozu
|
garoon
|
The "Scheduler" function in Cybozu Garoon before 4.2.2 allows remote attackers to redirect users to arbitrary websites.
|
CWE-601
Open Redirect
|
CVE-2016-1213
|
2024-11-21 11:45 |
2017-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269398
|
9.8 |
CRITICAL
Network
|
cybozu
|
garoon
|
Cybozu Garoon before 4.2.2 allows remote attackers to bypass login authentication via vectors related to API use.
|
CWE-287
Improper Authentication
|
CVE-2016-1219
|
2024-11-21 11:45 |
2017-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269399
|
9.8 |
CRITICAL
Network
|
google
|
android
|
HTTP header injection vulnerability in the URLConnection class in Android OS 2.2 through 6.0 allows remote attackers to execute arbitrary scripts or set arbitrary values in cookies.
|
CWE-74
Injection
|
CVE-2016-1155
|
2024-11-21 11:45 |
2017-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269400
|
7.5 |
HIGH
Network
|
docomo
|
shoplat
|
Shoplat App for iOS 1.10.00 through 1.18.00 does not properly verify SSL certificates.
|
CWE-295
Improper Certificate Validation
|
CVE-2016-1132
|
2024-11-21 11:45 |
2017-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|