CVE-2013-5035
4.9
Vector
AV:N/AC:M/Au:S/C:P/I:P/A:N
Exploitability: 6.8 / Impact: 4.9
Source: NVD
Description
Multiple race conditions in HtmlCleaner before 2.6, as used in Open-Xchange AppSuite 7.2.2 before rev13 and other products, allow remote authenticated users to read the private e-mail of other persons in opportunistic circumstances by leveraging lack of thread safety and performing a rapid series of (1) mail-sending or (2) draft-saving operations.
Affected (20)
Products: Htmlcleaner Project: Htmlcleaner · Open Xchange: Open Xchange Appsuite
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.5 | |
| Version 7.2.2 |
References (4)
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
Timeline
No history available yet.