CVE-2014-5236
31.01.2020, 22:15
Multiple absolute path traversal vulnerabilities in documentconverter in Open-Xchange (OX) AppSuite before 7.4.2-rev10 and 7.6.x before 7.6.0-rev10 allow remote attackers to read application files via a full pathname in a crafted (1) OLE Object or (2) image in an OpenDocument text file.
Vendor | Product | Version |
---|---|---|
open-xchange | open-xchange_appsuite | 𝑥 ≤ 7.4.1 |
open-xchange | open-xchange_appsuite | 7.4.2 |
open-xchange | open-xchange_appsuite | 7.4.2:revision1 |
open-xchange | open-xchange_appsuite | 7.4.2:revision10 |
open-xchange | open-xchange_appsuite | 7.4.2:revision2 |
open-xchange | open-xchange_appsuite | 7.4.2:revision3 |
open-xchange | open-xchange_appsuite | 7.4.2:revision4 |
open-xchange | open-xchange_appsuite | 7.4.2:revision5 |
open-xchange | open-xchange_appsuite | 7.4.2:revision6 |
open-xchange | open-xchange_appsuite | 7.4.2:revision7 |
open-xchange | open-xchange_appsuite | 7.4.2:revision8 |
open-xchange | open-xchange_appsuite | 7.4.2:revision9 |
open-xchange | open-xchange_appsuite | 7.6.0 |
open-xchange | open-xchange_appsuite | 7.6.0:revision1 |
open-xchange | open-xchange_appsuite | 7.6.0:revision2 |
open-xchange | open-xchange_appsuite | 7.6.0:revision3 |
open-xchange | open-xchange_appsuite | 7.6.0:revision4 |
open-xchange | open-xchange_appsuite | 7.6.0:revision5 |
open-xchange | open-xchange_appsuite | 7.6.0:revision6 |
open-xchange | open-xchange_appsuite | 7.6.0:revision7 |
open-xchange | open-xchange_appsuite | 7.6.0:revision8 |
𝑥
= Vulnerable software versions
References