Vulnerabilities
Vulnerable Software
Zarafa:  >> Zarafa  >> 7.1.10  Security Vulnerabilities
kopano-ical (formerly zarafa-ical) in Kopano Groupware Core through 8.7.16, 9.x through 9.1.0, 10.x through 10.0.7, and 11.x through 11.0.1 and Zarafa 6.30.x through 7.2.x allows memory exhaustion via long HTTP headers.
CVSS Score
7.5
EPSS Score
0.004
Published
2021-03-31
Zarafa WebAccess 7.1.10 and WebApp 1.6 beta uses weak permissions (644) for config.php, which allows local users to obtain sensitive information by reading the PHP session files. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-0103.
CVSS Score
2.1
EPSS Score
0.0
Published
2014-10-20


Contact Us

Shodan ® - All rights reserved