Cybozu Remote Service
by Cybozu
CVEs (16)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-20807 | 0.00 | — | 0.00 | Oct 13, 2021 | Cross-site scripting vulnerability in the management screen of Cybozu Remote Service 3.0.0 to 3.1.9 allows a remote attacker to inject an arbitrary script via unspecified vectors. | |||
| CVE-2021-20806 | 0.00 | — | 0.00 | Oct 13, 2021 | Open redirect vulnerability in Cybozu Remote Service 3.0.0 to 3.1.9 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors. | |||
| CVE-2021-20805 | 0.00 | — | 0.00 | Oct 13, 2021 | Cross-site scripting vulnerability in the management screen of Cybozu Remote Service 3.1.7 to 3.1.9 allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors. | |||
| CVE-2021-20804 | 0.00 | — | 0.00 | Oct 13, 2021 | Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote authenticated attacker to cause a denial of service (DoS) condition via unspecified vectors. | |||
| CVE-2021-20803 | 0.00 | — | 0.00 | Oct 13, 2021 | Operation restriction bypass in the management screen of Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote authenticated attacker to alter the data of the management screen. | |||
| CVE-2021-20802 | 0.00 | — | 0.00 | Oct 13, 2021 | HTTP header injection vulnerability in Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote attacker to alter the information stored in the product. | |||
| CVE-2021-20801 | 0.00 | — | 0.00 | Oct 13, 2021 | Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote authenticated attacker to conduct XML External Entity (XXE) attacks and obtain the information stored in the product via unspecified vectors. This issue occurs only when using Mozilla Firefox. | |||
| CVE-2021-20800 | 0.00 | — | 0.00 | Oct 13, 2021 | Cross-site scripting vulnerability in the management screen of Cybozu Remote Service 3.1.8 allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors. | |||
| CVE-2021-20799 | 0.00 | — | 0.00 | Oct 13, 2021 | Cross-site scripting vulnerability in the management screen of Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors. | |||
| CVE-2021-20798 | 0.00 | — | 0.00 | Oct 13, 2021 | Cross-site scripting vulnerability in the management screen of Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors. | |||
| CVE-2021-20797 | 0.00 | — | 0.00 | Oct 13, 2021 | Cross-site script inclusion vulnerability in the management screen of Cybozu Remote Service 3.1.8 allows a remote authenticated attacker to obtain the information stored in the product. This issue occurs only when using Mozilla Firefox. | |||
| CVE-2021-20796 | 0.00 | — | 0.00 | Oct 13, 2021 | Directory traversal vulnerability in the management screen of Cybozu Remote Service 3.1.8 allows a remote authenticated attacker to upload an arbitrary file via unspecified vectors. | |||
| CVE-2021-20795 | 0.00 | — | 0.00 | Oct 13, 2021 | Cross-site request forgery (CSRF) vulnerability in the management screen of Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote attacker to hijack the authentication of administrators and unintended operations may be performed via unspecified vectors. | |||
| CVE-2018-16170 | 0.00 | — | 0.01 | Jan 9, 2019 | Directory traversal vulnerability in Cybozu Remote Service 3.0.0 to 3.1.8 for Windows allows remote authenticated attackers to read arbitrary files via unspecified vectors. | |||
| CVE-2018-16169 | 0.00 | — | 0.01 | Jan 9, 2019 | Cybozu Remote Service 3.0.0 to 3.1.0 allows remote authenticated attackers to upload and execute Java code file on the server via unspecified vectors. | |||
| CVE-2018-16171 | 0.00 | — | 0.01 | Jan 9, 2019 | Directory traversal vulnerability in Cybozu Remote Service 3.0.0 to 3.1.8 allows remote attackers to execute Java code file on the server via unspecified vectors. |
- CVE-2021-20807Oct 13, 2021risk 0.00cvss —epss 0.00
Cross-site scripting vulnerability in the management screen of Cybozu Remote Service 3.0.0 to 3.1.9 allows a remote attacker to inject an arbitrary script via unspecified vectors.
- CVE-2021-20806Oct 13, 2021risk 0.00cvss —epss 0.00
Open redirect vulnerability in Cybozu Remote Service 3.0.0 to 3.1.9 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
- CVE-2021-20805Oct 13, 2021risk 0.00cvss —epss 0.00
Cross-site scripting vulnerability in the management screen of Cybozu Remote Service 3.1.7 to 3.1.9 allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors.
- CVE-2021-20804Oct 13, 2021risk 0.00cvss —epss 0.00
Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote authenticated attacker to cause a denial of service (DoS) condition via unspecified vectors.
- CVE-2021-20803Oct 13, 2021risk 0.00cvss —epss 0.00
Operation restriction bypass in the management screen of Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote authenticated attacker to alter the data of the management screen.
- CVE-2021-20802Oct 13, 2021risk 0.00cvss —epss 0.00
HTTP header injection vulnerability in Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote attacker to alter the information stored in the product.
- CVE-2021-20801Oct 13, 2021risk 0.00cvss —epss 0.00
Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote authenticated attacker to conduct XML External Entity (XXE) attacks and obtain the information stored in the product via unspecified vectors. This issue occurs only when using Mozilla Firefox.
- CVE-2021-20800Oct 13, 2021risk 0.00cvss —epss 0.00
Cross-site scripting vulnerability in the management screen of Cybozu Remote Service 3.1.8 allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors.
- CVE-2021-20799Oct 13, 2021risk 0.00cvss —epss 0.00
Cross-site scripting vulnerability in the management screen of Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors.
- CVE-2021-20798Oct 13, 2021risk 0.00cvss —epss 0.00
Cross-site scripting vulnerability in the management screen of Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors.
- CVE-2021-20797Oct 13, 2021risk 0.00cvss —epss 0.00
Cross-site script inclusion vulnerability in the management screen of Cybozu Remote Service 3.1.8 allows a remote authenticated attacker to obtain the information stored in the product. This issue occurs only when using Mozilla Firefox.
- CVE-2021-20796Oct 13, 2021risk 0.00cvss —epss 0.00
Directory traversal vulnerability in the management screen of Cybozu Remote Service 3.1.8 allows a remote authenticated attacker to upload an arbitrary file via unspecified vectors.
- CVE-2021-20795Oct 13, 2021risk 0.00cvss —epss 0.00
Cross-site request forgery (CSRF) vulnerability in the management screen of Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote attacker to hijack the authentication of administrators and unintended operations may be performed via unspecified vectors.
- CVE-2018-16170Jan 9, 2019risk 0.00cvss —epss 0.01
Directory traversal vulnerability in Cybozu Remote Service 3.0.0 to 3.1.8 for Windows allows remote authenticated attackers to read arbitrary files via unspecified vectors.
- CVE-2018-16169Jan 9, 2019risk 0.00cvss —epss 0.01
Cybozu Remote Service 3.0.0 to 3.1.0 allows remote authenticated attackers to upload and execute Java code file on the server via unspecified vectors.
- CVE-2018-16171Jan 9, 2019risk 0.00cvss —epss 0.01
Directory traversal vulnerability in Cybozu Remote Service 3.0.0 to 3.1.8 allows remote attackers to execute Java code file on the server via unspecified vectors.