Cybozu Office CVE-2013-4703 Cross Site Scripting Vulnerability
BID:62288
Info
Cybozu Office CVE-2013-4703 Cross Site Scripting Vulnerability
| Bugtraq ID: | 62288 |
| Class: | Input Validation Error |
| CVE: |
CVE-2013-4703 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 10 2013 12:00AM |
| Updated: | Sep 10 2013 12:00AM |
| Credit: | Motoki Nishio of VALTES |
| Vulnerable: |
Cybozu Office 9 Cybozu Office 8.1.1 Cybozu Office 8 Cybozu Office 7 |
| Not Vulnerable: | |
Discussion
Cybozu Office CVE-2013-4703 Cross Site Scripting Vulnerability
Cybozu Office is prone to a cross-site scripting vulnerability.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may let the attacker steal cookie-based authentication credentials and launch other attacks.
Versions prior to Cybozu Office 9.3.1 are vulnerable.
Cybozu Office is prone to a cross-site scripting vulnerability.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may let the attacker steal cookie-based authentication credentials and launch other attacks.
Versions prior to Cybozu Office 9.3.1 are vulnerable.
References
Cybozu Office CVE-2013-4703 Cross Site Scripting Vulnerability
References:
References: