|
265181
|
6.5 |
MEDIUM
Network
|
cybozu
|
office
|
Cybozu Office 9.0.0 through 10.4.0 allows remote attackers to cause a denial of service.
|
CWE-399
Resource Management Errors
|
CVE-2016-4871
|
2024-11-21 11:53 |
2017-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265182
|
5.4 |
MEDIUM
Network
|
cybozu
|
office
|
Cross-site scripting vulnerability in Cybozu Office 9.0.0 to 10.4.0 allows remote authenticated attackers to inject arbitrary web script or HTML via the Schedule function.
|
CWE-79
Cross-site Scripting
|
CVE-2016-4870
|
2024-11-21 11:53 |
2017-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265183
|
6.5 |
MEDIUM
Network
|
cybozu
|
office
|
Cybozu Office 9.0.0 to 10.4.0 allow remote attackers to obtain session information via a page where CGI environment variables are displayed.
|
CWE-200
Information Exposure
|
CVE-2016-4869
|
2024-11-21 11:53 |
2017-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265184
|
4.3 |
MEDIUM
Network
|
cybozu
|
office
|
Email header injection vulnerability in Cybozu Office 9.0.0 to 10.4.0 allows remote attackers to inject arbitrary email headers to send unintended emails via specially crafted requests.
|
CWE-20
Improper Input Validation
|
CVE-2016-4868
|
2024-11-21 11:53 |
2017-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265185
|
4.3 |
MEDIUM
Network
|
cybozu
|
office
|
Cybozu Office 9.0.0 to 10.4.0 allows remote authenticated attackers to bypass access restriction to view unauthorized project information via the Project function.
|
CWE-200
Information Exposure
|
CVE-2016-4867
|
2024-11-21 11:53 |
2017-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265186
|
4.8 |
MEDIUM
Network
|
cybozu
|
office
|
Cross-site scripting vulnerability in Cybozu Office 9.0.0 to 10.4.0 allows attackers with administrator rights to inject arbitrary web script or HTML via the Project function.
|
CWE-79
Cross-site Scripting
|
CVE-2016-4866
|
2024-11-21 11:53 |
2017-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265187
|
4.8 |
MEDIUM
Network
|
cybozu
|
office
|
Cross-site scripting vulnerability in Cybozu Office 9.0.0 to 10.4.0 allows attackers with administrator rights to inject arbitrary web script or HTML via the Customapp function.
|
CWE-79
Cross-site Scripting
|
CVE-2016-4865
|
2024-11-21 11:53 |
2017-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265188
|
5.3 |
MEDIUM
Network
|
zohocorp
|
servicedesk_plus
|
ZOHO ManageEngine ServiceDesk Plus before 9.2 uses an insecure method for generating cookies, which makes it easier for attackers to obtain sensitive password information by leveraging access to a co…
|
CWE-254
7PK - Security Features
|
CVE-2016-4890
|
2024-11-21 11:53 |
2017-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265189
|
8.8 |
HIGH
Network
|
zohocorp
|
servicedesk_plus
|
ZOHO ManageEngine ServiceDesk Plus before 9.0 allows remote authenticated guest users to have unspecified impact by leveraging failure to restrict access to unknown functions.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-4889
|
2024-11-21 11:53 |
2017-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265190
|
5.4 |
MEDIUM
Network
|
zohocorp
|
servicedesk_plus
|
Cross-site scripting (XSS) vulnerability in ZOHO ManageEngine ServiceDesk Plus before 9.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2016-4888
|
2024-11-21 11:53 |
2017-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|