Cybozu Products Multiple Cross-Site Scripting and Denial of Service Vulnerabilities
BID:26812
Info
Cybozu Products Multiple Cross-Site Scripting and Denial of Service Vulnerabilities
| Bugtraq ID: | 26812 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 27 2007 12:00AM |
| Updated: | Dec 12 2007 04:42PM |
| Credit: | JVN reported these vulnerabilities. |
| Vulnerable: |
Cybozu Office 6.6 Build 1.3 Cybozu Office 6.5 Cybozu Garoon 1.5(4.1) |
| Not Vulnerable: |
Cybozu Office 6.6 (1.4) Cybozu Garoon 1.5(4.2) |
Discussion
Cybozu Products Multiple Cross-Site Scripting and Denial of Service Vulnerabilities
Cybozu products are prone to multiple cross-site scripting and denial-of-service vulnerabilities because the applications fail to properly handle user-supplied input.
An attacker may leverage these issues to cause denial-of-service conditions or to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Cybozu products are prone to multiple cross-site scripting and denial-of-service vulnerabilities because the applications fail to properly handle user-supplied input.
An attacker may leverage these issues to cause denial-of-service conditions or to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Exploit / POC
Cybozu Products Multiple Cross-Site Scripting and Denial of Service Vulnerabilities
Attackers can exploit cross-site scripting issues by enticing an unsuspecting user to follow a malicious URI.
Attackers can exploit cross-site scripting issues by enticing an unsuspecting user to follow a malicious URI.
Solution / Fix
Cybozu Products Multiple Cross-Site Scripting and Denial of Service Vulnerabilities
Solution:
The vendor released updates to address these issues. Please see the references for more information.
Solution:
The vendor released updates to address these issues. Please see the references for more information.
References
Cybozu Products Multiple Cross-Site Scripting and Denial of Service Vulnerabilities
References:
References:
- Advisory CY07-07-001 (Cybozu)
- Advisory CY07-07-002 (Cybozu)
- Advisory CY07-07-003 (Cybozu)
- JVN#50342989 (JVN)
- JVN#77414947 (JVN)
- JVN#77730435 (JVN)
- JVN#90712589 (JVN)