CVE-2013-6003
Severity CVSS v4.0:
Pending analysis
Type:
CWE-20
Input Validation
Publication date:
05/12/2013
Last modified:
11/04/2025
Description
CRLF injection vulnerability in Cybozu Garoon 3.1 through 3.5 SP5, when Phone Messages forwarding is enabled, allows remote authenticated users to inject arbitrary e-mail headers via unspecified vectors.
Impact
Base Score 2.0
3.50
Severity 2.0
LOW
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:cybozu:garoon:3.1:*:*:*:*:*:*:* | ||
cpe:2.3:a:cybozu:garoon:3.1:sp1:*:*:*:*:*:* | ||
cpe:2.3:a:cybozu:garoon:3.1:sp2:*:*:*:*:*:* | ||
cpe:2.3:a:cybozu:garoon:3.1:sp3:*:*:*:*:*:* | ||
cpe:2.3:a:cybozu:garoon:3.5:*:*:*:*:*:*:* | ||
cpe:2.3:a:cybozu:garoon:3.5:sp1:*:*:*:*:*:* | ||
cpe:2.3:a:cybozu:garoon:3.5:sp2:*:*:*:*:*:* | ||
cpe:2.3:a:cybozu:garoon:3.5:sp3:*:*:*:*:*:* | ||
cpe:2.3:a:cybozu:garoon:3.5:sp4:*:*:*:*:*:* | ||
cpe:2.3:a:cybozu:garoon:3.5:sp5:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://cs.cybozu.co.jp/information/20131202up01.php
- http://jvn.jp/en/jp/JVN84221103/index.html
- http://jvndb.jvn.jp/jvndb/JVNDB-2013-000116
- https://support.cybozu.com/ja-jp/article/6121
- http://cs.cybozu.co.jp/information/20131202up01.php
- http://jvn.jp/en/jp/JVN84221103/index.html
- http://jvndb.jvn.jp/jvndb/JVNDB-2013-000116
- https://support.cybozu.com/ja-jp/article/6121