CVE-2011-1334: XSS
Cross-site scripting (XSS) vulnerability in Cybozu Office 6, Cybozu Garoon 2.0.0 through 2.1.3, Cybozu Dezie before 6.1, Cybozu MailWise before 3.1, and Cybozu Collaborex before 1.5 allows remote attackers to inject arbitrary web script or HTML via vectors related to "downloading graphic files from the mail system."
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2011-1334?
CVE-2011-1334 has a medium severity rating due to its potential for cross-site scripting attacks.
How do I fix CVE-2011-1334?
To fix CVE-2011-1334, update to the latest versions of affected Cybozu products that have patched this vulnerability.
Which versions of Cybozu software are affected by CVE-2011-1334?
CVE-2011-1334 affects Cybozu Office 6, Garoon versions 2.0.0 to 2.1.3, Dezie versions below 6.1, MailWise versions below 3.1, and Collaborex before 1.5.
What types of attacks can be executed due to CVE-2011-1334?
Exploiting CVE-2011-1334 can allow attackers to inject arbitrary web scripts or HTML into web applications.
Is CVE-2011-1334 exploit code publicly available?
Yes, there is exploit code available for CVE-2011-1334, making it crucial for users of affected software to apply necessary updates.