First published: Wed Jun 29 2011(Updated: )
Cross-site scripting (XSS) vulnerability in Cybozu Office 6, 7, and 8 before 8.1.1 allows remote attackers to inject arbitrary web script or HTML via vectors related to the "address book and user list functions."
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Cybozu Office | =7 | |
Cybozu Office | =8 | |
Cybozu Office | =6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-1335 has a medium severity rating due to its potential for exploitation through cross-site scripting.
To fix CVE-2011-1335, upgrade Cybozu Office to version 8.1.1 or later.
CVE-2011-1335 affects Cybozu Office versions 6, 7, and 8 prior to version 8.1.1.
CVE-2011-1335 can allow remote attackers to inject arbitrary web scripts or HTML into the application.
CVE-2011-1335 is related to vulnerabilities in the address book and user list functions of Cybozu Office.