Open-Xchange Server and OX App Suite CVE-2014-8993 Unspecified HTML Injection Vulnerability
BID:71888
Info
Open-Xchange Server and OX App Suite CVE-2014-8993 Unspecified HTML Injection Vulnerability
| Bugtraq ID: | 71888 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-8993 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 05 2015 12:00AM |
| Updated: | Jan 05 2015 12:00AM |
| Credit: | John de Kroon of Voiceworks B.V. |
| Vulnerable: |
Open-Xchange Open-Xchange Server 6 7.6.1 Open-Xchange Open-Xchange Server 6 7.6 Open-Xchange Open-Xchange AppSuite 7.6.1 Open-Xchange Open-Xchange AppSuite 7.6 |
| Not Vulnerable: |
Open-Xchange Open-Xchange Server 6 7.6.1-rev11 Open-Xchange Open-Xchange Server 6 7.6.0-rev32 Open-Xchange Open-Xchange Server 6 7.4.2-rev40 Open-Xchange Open-Xchange AppSuite 7.6.1-rev11 Open-Xchange Open-Xchange AppSuite 7.6.0-rev32 Open-Xchange Open-Xchange AppSuite 7.4.2-rev40 |
Exploit / POC
Open-Xchange Server and OX App Suite CVE-2014-8993 Unspecified HTML Injection Vulnerability
Attackers can use a browser to exploit this issue.
Attackers can use a browser to exploit this issue.
Solution / Fix
Open-Xchange Server and OX App Suite CVE-2014-8993 Unspecified HTML Injection Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.