CVE-2011-2677

Cybozu Office < 8.0.0 - Authenticated Information Disclosure via URL Manipulation

Title source: llm
STIX 2.1

Description

Cybozu Office before 8.0.0 allows remote authenticated users to bypass intended access restrictions and access sensitive information (time card and attendance) via unspecified vectors related to manipulation of a URL.

References (7)

Core 7
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/76124
Various Sources x_refsource_confirm
http://cs.cybozu.co.jp/information/20111005notice01.php
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/70411
Third Party Advisory third-party-advisory x_refsource_jvn
http://jvn.jp/en/jp/JVN84838479/index.html
Third Party Advisory third-party-advisory x_refsource_jvndb
http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-000079.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/50015
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/46321

Scores

EPSS 0.0032
EPSS Percentile 55.4%

Details

CWE
CWE-264
Status published
Products (2)
cybozu/office 6
cybozu/office < 7
Published Oct 21, 2011
Tracked Since Feb 18, 2026