CVE-2013-6905: XSS
Cross-site scripting (XSS) vulnerability in a phone component in Cybozu Garoon before 3.7.0, when Internet Explorer or Firefox is used, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-6905?
CVE-2013-6905 is classified as a cross-site scripting (XSS) vulnerability with potential for significant impact if exploited.
How do I fix CVE-2013-6905?
To fix CVE-2013-6905, upgrade to Cybozu Garoon version 3.7.0 or later, which contains the necessary security patches.
Which versions of Cybozu Garoon are affected by CVE-2013-6905?
CVE-2013-6905 affects Cybozu Garoon versions prior to 3.7.0, including several subversions from 2.0 to 3.5.
Can CVE-2013-6905 be exploited in Internet Explorer and Firefox?
Yes, CVE-2013-6905 can be exploited in Internet Explorer and Firefox, enabling attackers to inject arbitrary web scripts.
What risks are associated with CVE-2013-6905?
The risks associated with CVE-2013-6905 include unauthorized access and manipulation of user data through injected scripts.