Lucene search

K
cveMitreCVE-2008-6744
HistoryApr 23, 2009 - 5:30 p.m.

CVE-2008-6744

2009-04-2317:30:00
CWE-352
mitre
web.nvd.nist.gov
23
cve-2008-6744
cross-site request forgery
csrf vulnerability
cybozu office 6
cybozu dezie
cybozu garoon
remote attackers
authentication hijacking
nvd

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

7.3

Confidence

Low

EPSS

0.003

Percentile

71.2%

Cross-site request forgery (CSRF) vulnerability in Cybozu Office 6, Cybozu Dezie before 6.0(1.0), and Cybozu Garoon 2.0.0 through 2.1.3 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

Affected configurations

Nvd
Node
cybozucybozu_dezieRange6
OR
cybozucybozu_garoonMatch2.0.0
OR
cybozucybozu_garoonMatch2.0.1
OR
cybozucybozu_garoonMatch2.0.2
OR
cybozucybozu_garoonMatch2.0.3
OR
cybozucybozu_garoonMatch2.0.4
OR
cybozucybozu_garoonMatch2.0.5
OR
cybozucybozu_garoonMatch2.0.6
OR
cybozucybozu_garoonMatch2.1.0
OR
cybozucybozu_garoonMatch2.1.1
OR
cybozucybozu_garoonMatch2.1.2
OR
cybozucybozu_garoonMatch2.1.3
OR
cybozucybozu_officeMatch6
VendorProductVersionCPE
cybozucybozu_dezie*cpe:2.3:a:cybozu:cybozu_dezie:*:*:*:*:*:*:*:*
cybozucybozu_garoon2.0.0cpe:2.3:a:cybozu:cybozu_garoon:2.0.0:*:*:*:*:*:*:*
cybozucybozu_garoon2.0.1cpe:2.3:a:cybozu:cybozu_garoon:2.0.1:*:*:*:*:*:*:*
cybozucybozu_garoon2.0.2cpe:2.3:a:cybozu:cybozu_garoon:2.0.2:*:*:*:*:*:*:*
cybozucybozu_garoon2.0.3cpe:2.3:a:cybozu:cybozu_garoon:2.0.3:*:*:*:*:*:*:*
cybozucybozu_garoon2.0.4cpe:2.3:a:cybozu:cybozu_garoon:2.0.4:*:*:*:*:*:*:*
cybozucybozu_garoon2.0.5cpe:2.3:a:cybozu:cybozu_garoon:2.0.5:*:*:*:*:*:*:*
cybozucybozu_garoon2.0.6cpe:2.3:a:cybozu:cybozu_garoon:2.0.6:*:*:*:*:*:*:*
cybozucybozu_garoon2.1.0cpe:2.3:a:cybozu:cybozu_garoon:2.1.0:*:*:*:*:*:*:*
cybozucybozu_garoon2.1.1cpe:2.3:a:cybozu:cybozu_garoon:2.1.1:*:*:*:*:*:*:*
Rows per page:
1-10 of 131

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

7.3

Confidence

Low

EPSS

0.003

Percentile

71.2%

Related for CVE-2008-6744