CVE-2017-7666

CVSS v3 Score
8.8
High
CVSS v2 Score
6.8
Medium

Vulnerability Description

Apache OpenMeetings 1.0.0 is vulnerable to Cross-Site Request Forgery (CSRF) attacks, XSS attacks, click-jacking, and MIME based attacks.

CVSS:8.8(High)

Argument injection vulnerability involving Microsoft Outlook and Outlook Express, when certain URIs are registered, allows remote attackers to conduct cross-browser scripting attacks and execute arbit...

CWE-792007
CVSS:8.8(High)

The RESTful Web Services (restws) module 7.x-1.x before 7.x-1.4 and 7.x-2.x before 7.x-2.1 for Drupal does not properly restrict access to entity write operations, which makes it easier for remote aut...

CWE-792013
CVSS:8.8(High)

Horde Groupware Webmail Edition has CSRF and XSS when saving search as a virtual address book

CWE-792013
CVSS:8.8(High)

Multiple vulnerabilities in Cisco Data Center Network Manager (DCNM) Software could allow a remote attacker to inject arbitrary values into DCNM configuration parameters, redirect a user to a maliciou...

CWE-792017
CVSS:8.8(High)

An issue was discovered on Securifi Almond, Almond+, and Almond 2015 devices with firmware AL-R096. The device provides a user with the capability of blocking key words passing in the web traffic to p...

CWE-792017
CVSS:8.8(High)

Microsoft SharePoint Server allows an elevation of privilege vulnerability due to the way that it sanitizes a specially crafted web request to an affected SharePoint server, aka "SharePoint Server XSS...

CWE-792017