CVE-2014-5236

Multiple absolute path traversal vulnerabilities in documentconverter in Open-Xchange (OX) AppSuite before 7.4.2-rev10 and 7.6.x before 7.6.0-rev10 allow remote attackers to read application files via a full pathname in a crafted (1) OLE Object or (2) image in an OpenDocument text file.
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 89%
VendorProductVersion
open-xchangeopen-xchange_appsuite
𝑥
≤ 7.4.1
open-xchangeopen-xchange_appsuite
7.4.2
open-xchangeopen-xchange_appsuite
7.4.2:revision1
open-xchangeopen-xchange_appsuite
7.4.2:revision10
open-xchangeopen-xchange_appsuite
7.4.2:revision2
open-xchangeopen-xchange_appsuite
7.4.2:revision3
open-xchangeopen-xchange_appsuite
7.4.2:revision4
open-xchangeopen-xchange_appsuite
7.4.2:revision5
open-xchangeopen-xchange_appsuite
7.4.2:revision6
open-xchangeopen-xchange_appsuite
7.4.2:revision7
open-xchangeopen-xchange_appsuite
7.4.2:revision8
open-xchangeopen-xchange_appsuite
7.4.2:revision9
open-xchangeopen-xchange_appsuite
7.6.0
open-xchangeopen-xchange_appsuite
7.6.0:revision1
open-xchangeopen-xchange_appsuite
7.6.0:revision2
open-xchangeopen-xchange_appsuite
7.6.0:revision3
open-xchangeopen-xchange_appsuite
7.6.0:revision4
open-xchangeopen-xchange_appsuite
7.6.0:revision5
open-xchangeopen-xchange_appsuite
7.6.0:revision6
open-xchangeopen-xchange_appsuite
7.6.0:revision7
open-xchangeopen-xchange_appsuite
7.6.0:revision8
𝑥
= Vulnerable software versions