Show filters
64 Total Results
Displaying 61-64 of 64
Sort by:
Attacker Value
Unknown

CVE-2013-7091

Disclosure Date: December 13, 2013 (last updated October 05, 2023)
Directory traversal vulnerability in /res/I18nMsg,AjxMsg,ZMsg,ZmMsg,AjxKeys,ZmKeys,ZdMsg,Ajx%20TemplateMsg.js.zgz in Zimbra 7.2.2 and 8.0.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the skin parameter. NOTE: this can be leveraged to execute arbitrary code by obtaining LDAP credentials and accessing the service/admin/soap API.
0
Attacker Value
Unknown

CVE-2013-5119

Disclosure Date: September 23, 2013 (last updated October 05, 2023)
Zimbra Collaboration Suite (ZCS) 6.0.16 and earlier allows man-in-the-middle attackers to obtain access by sniffing the network and replaying the ZM_AUTH_TOKEN token.
0
Attacker Value
Unknown

CVE-2012-1213

Disclosure Date: February 24, 2012 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in zimbra/h/calendar in Zimbra Web Client in Zimbra Collaboration Suite (ZCS) 6.x before 6.0.15 and 7.x before 7.1.3 allows remote attackers to inject arbitrary web script or HTML via the view parameter.
0
Attacker Value
Unknown

CVE-2012-0903

Disclosure Date: January 20, 2012 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Zimbra Desktop 7.1.2 b10978 allow remote attackers to inject arbitrary web script or HTML via the (1) Username or (2) MailBox Name.
0