CVE-2013-3106
published 2013-09-05CVE-2013-3106: Multiple cross-site scripting (XSS) vulnerabilities in Open-Xchange AppSuite and Server before 6.20.7 rev18, 6.22.0 before rev16, 6.22.1 before rev19, 7.0.1…
PriorityP418medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
0.94%
56.5th percentile
Multiple cross-site scripting (XSS) vulnerabilities in Open-Xchange AppSuite and Server before 6.20.7 rev18, 6.22.0 before rev16, 6.22.1 before rev19, 7.0.1 before rev7, 7.0.2 before rev11, and 7.2.0 before rev8 allow remote attackers to inject arbitrary web script or HTML via (1) embedded VBScript, (2) object/data Base64 content, (3) a Content-Type header, or (4) UTF-16 encoding, aka Bug IDs 25957, 26237, 26243, and 26244.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| open-xchange | open-xchange_appsuite | — | — |
| open-xchange | open-xchange_appsuite | — | — |
| open-xchange | open-xchange_appsuite | — | — |
| open-xchange | open-xchange_appsuite | — | — |
| open-xchange | open-xchange_appsuite | — | — |
| open-xchange | open-xchange_appsuite | — | — |
| open-xchange | open-xchange_server | — | — |
| open-xchange | open-xchange_server | — | — |
| open-xchange | open-xchange_server | — | — |
| open-xchange | open-xchange_server | — | — |
| open-xchange | open-xchange_server | — | — |
| open-xchange | open-xchange_server | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-fjqg-74r6-7pp5: Multiple cross-site scripting (XSS) vulnerabilities in Open-Xchange AppSuite and Server before 6
ghsa_unreviewed·2022-05-17
CVE-2013-3106 [MEDIUM] CWE-79 GHSA-fjqg-74r6-7pp5: Multiple cross-site scripting (XSS) vulnerabilities in Open-Xchange AppSuite and Server before 6
Multiple cross-site scripting (XSS) vulnerabilities in Open-Xchange AppSuite and Server before 6.20.7 rev18, 6.22.0 before rev16, 6.22.1 before rev19, 7.0.1 before rev7, 7.0.2 before rev11, and 7.2.0 before rev8 allow remote attackers to inject arbitrary web script or HTML via (1) embedded VBScript, (2) object/data Base64 content, (3) a Content-Type header, or (4) UTF-16 encoding, aka Bug IDs 25957, 26237, 26243, and 26244.
GHSA
GHSA-f775-4rjm-m64p: Cross-site scripting (XSS) vulnerability in Open-Xchange AppSuite and Server before 6
ghsa_unreviewed·2022-05-17·CVSS 4.3
CVE-2013-5698 [MEDIUM] CWE-79 GHSA-f775-4rjm-m64p: Cross-site scripting (XSS) vulnerability in Open-Xchange AppSuite and Server before 6
Cross-site scripting (XSS) vulnerability in Open-Xchange AppSuite and Server before 6.22.0 rev16, 6.22.1 before rev19, 7.0.1 before rev7, 7.0.2 before rev11, and 7.2.0 before rev8 allows remote authenticated users to inject arbitrary web script or HTML via a delivery=view action, aka Bug ID 26373, a different vulnerability than CVE-2013-3106.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2013-09-05
Published