Multiple Cybozu Products Multiple Cross Site Scripting Vulnerabilities
18 Jul. 2012
Summary
Multiple Cybozu products are prone to multiple cross-site scripting vulnerabilities because they fail to sufficiently sanitize user-supplied input.
Credit:
The original article can be found at: http://www.securityfocus.com/bid/48446
The information has been provided by Sen UENO of Tricorder Co. Ltd. and NetAgent Co. Ltd..
Vulnerable Systems:
* Cybozu Garoon 2.1.3 and prior
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Vendor Status:
Vendor as issued an updated vulnerability.