CVE-2011-1335: XSS
Published Jun 29, 2011
·Updated
Cross-site scripting (XSS) vulnerability in Cybozu Office 6, 7, and 8 before 8.1.1 allows remote attackers to inject arbitrary web script or HTML via vectors related to the "address book and user list functions."
Affected Software
3 affected components
Cybozu Office=7
Cybozu Office=8
Cybozu Office=6
Remediation
Patch Available
Event History
Jun 29, 2011
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-1335?
CVE-2011-1335 has a medium severity rating due to its potential for exploitation through cross-site scripting.
2
How do I fix CVE-2011-1335?
To fix CVE-2011-1335, upgrade Cybozu Office to version 8.1.1 or later.
3
Which software versions are affected by CVE-2011-1335?
CVE-2011-1335 affects Cybozu Office versions 6, 7, and 8 prior to version 8.1.1.
4
What types of attacks can CVE-2011-1335 allow?
CVE-2011-1335 can allow remote attackers to inject arbitrary web scripts or HTML into the application.
5
What functions are related to the CVE-2011-1335 vulnerability?
CVE-2011-1335 is related to vulnerabilities in the address book and user list functions of Cybozu Office.