CVE-2022-26838
- EPSS 0.61%
- Veröffentlicht 03.08.2023 15:15:16
- Zuletzt bearbeitet 21.11.2024 06:54:37
Path traversal vulnerability in Importing Mobile Device Data of Cybozu Remote Service 3.1.2 allows a remote authenticated attacker to cause a denial-of-service (DoS) condition.
CVE-2021-20807
- EPSS 0.35%
- Veröffentlicht 13.10.2021 09:15:08
- Zuletzt bearbeitet 21.11.2024 05:47:13
Cross-site scripting vulnerability in the management screen of Cybozu Remote Service 3.0.0 to 3.1.9 allows a remote attacker to inject an arbitrary script via unspecified vectors.
CVE-2021-20806
- EPSS 0.27%
- Veröffentlicht 13.10.2021 09:15:08
- Zuletzt bearbeitet 21.11.2024 05:47:13
Open redirect vulnerability in Cybozu Remote Service 3.0.0 to 3.1.9 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
CVE-2021-20805
- EPSS 0.21%
- Veröffentlicht 13.10.2021 09:15:08
- Zuletzt bearbeitet 21.11.2024 05:47:13
Cross-site scripting vulnerability in the management screen of Cybozu Remote Service 3.1.7 to 3.1.9 allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors.
CVE-2021-20804
- EPSS 0.49%
- Veröffentlicht 13.10.2021 09:15:08
- Zuletzt bearbeitet 21.11.2024 05:47:12
Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote authenticated attacker to cause a denial of service (DoS) condition via unspecified vectors.
CVE-2021-20803
- EPSS 0.15%
- Veröffentlicht 13.10.2021 09:15:08
- Zuletzt bearbeitet 21.11.2024 05:47:12
Operation restriction bypass in the management screen of Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote authenticated attacker to alter the data of the management screen.
CVE-2021-20802
- EPSS 0.35%
- Veröffentlicht 13.10.2021 09:15:08
- Zuletzt bearbeitet 21.11.2024 05:47:12
HTTP header injection vulnerability in Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote attacker to alter the information stored in the product.
CVE-2021-20798
- EPSS 0.21%
- Veröffentlicht 13.10.2021 09:15:07
- Zuletzt bearbeitet 21.11.2024 05:47:12
Cross-site scripting vulnerability in the management screen of Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors.
CVE-2021-20801
- EPSS 0.49%
- Veröffentlicht 13.10.2021 09:15:07
- Zuletzt bearbeitet 21.11.2024 05:47:12
Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote authenticated attacker to conduct XML External Entity (XXE) attacks and obtain the information stored in the product via unspecified vectors. This issue occurs only when using Mozilla Firefox.
CVE-2021-20800
- EPSS 0.21%
- Veröffentlicht 13.10.2021 09:15:07
- Zuletzt bearbeitet 21.11.2024 05:47:12
Cross-site scripting vulnerability in the management screen of Cybozu Remote Service 3.1.8 allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors.