[Forgot Password]
Login  Register Subscribe

30480

 
 

423868

 
 

254202

 
 

909

 
 

198060

 
 

282

Paid content will be excluded from the download.


Download | Alert*


CVE-2014-0103
WebAccess in Zarafa before 7.1.10 and WebApp before 1.6 stores credentials in cleartext, which allows local Apache users to obtain sensitive information by reading the PHP session files.

CVE-2015-3436
provider/server/ECServer.cpp in Zarafa Collaboration Platform (ZCP) before 7.1.13 and 7.2.x before 7.2.1 allows local users to write to arbitrary files via a symlink attack on /tmp/zarafa-upgrade-lock.

*OVAL
oval:org.secpod.oval:def:109131
CPE    23
cpe:/a:zarafa:zarafa:7.0
cpe:/a:zarafa:zarafa:7.0.4
cpe:/a:zarafa:zarafa:7.1.3
cpe:/a:zarafa:zarafa:7.0.3
...

© SecPod Technologies