Open-xchange

Ox Guard

11 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.16%
  • Published 02.11.2023 14:15:10
  • Last modified 21.11.2024 07:51:30

Users were able to set an arbitrary "product name" for OX Guard. The chosen value was not sufficiently sanitized before processing it at the user interface, allowing for indirect cross-site scripting attacks. Accounts that were temporarily taken over...

  • EPSS 0.45%
  • Published 30.04.2021 22:15:07
  • Last modified 21.11.2024 05:23:20

OX Guard 2.10.4 and earlier allows a Denial of Service via a WKS server that responds slowly or with a large amount of data.

  • EPSS 0.51%
  • Published 15.06.2020 15:15:09
  • Last modified 21.11.2024 05:40:36

OX Guard 2.10.3 and earlier allows XSS.

  • EPSS 0.21%
  • Published 15.06.2020 15:15:09
  • Last modified 21.11.2024 05:40:37

OX Guard 2.10.3 and earlier allows SSRF.

  • EPSS 0.17%
  • Published 03.07.2019 17:15:09
  • Last modified 21.11.2024 03:42:26

OX Guard 2.8.0 has CSRF.

Exploit
  • EPSS 0.87%
  • Published 15.12.2016 06:59:25
  • Last modified 12.04.2025 10:46:40

An issue was discovered in Open-Xchange OX Guard before 2.4.2-rev5. Script code which got injected to a mail with inline PGP signature gets executed when verifying the signature. Malicious script code can be executed within a user's context. This can...

Exploit
  • EPSS 0.87%
  • Published 15.12.2016 06:59:24
  • Last modified 12.04.2025 10:46:40

An issue was discovered in Open-Xchange OX Guard before 2.4.2-rev5. Script code and references to external websites can be injected to the names of PGP public keys. When requesting that key later on using a specific URL, such script code might get ex...

Exploit
  • EPSS 1.37%
  • Published 15.12.2016 06:59:22
  • Last modified 12.04.2025 10:46:40

An issue was discovered in Open-Xchange OX Guard before 2.4.2-rev5. Script code can be provided as parameter to the OX Guard guest reader web application. This allows cross-site scripting attacks against arbitrary users since no prior authentication ...

  • EPSS 0.2%
  • Published 15.12.2016 06:59:07
  • Last modified 12.04.2025 10:46:40

An issue was discovered in Open-Xchange OX Guard before 2.4.0-rev8. OX Guard uses an authentication token to identify and transfer guest users' credentials. The OX Guard API acts as a padding oracle by responding with different error codes depending...

  • EPSS 0.16%
  • Published 15.12.2016 06:59:00
  • Last modified 12.04.2025 10:46:40

An issue was discovered in Open-Xchange Guard before 2.2.0-rev8. The "getprivkeybyid" API call is used to download a PGP Private Key for a specific user after providing authentication credentials. Clients provide the "id" and "cid" parameter to speci...