PT-2006-4677 · Novell · Novell Groupwise Webaccess
Publicado
2006-08-11
·
Atualizado
2018-10-17
·
CVE-2006-3818
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Novell GroupWise WebAccess versions 6.5 before 20060721
Novell GroupWise WebAccess versions 7 before 20060727
Description
A cross-site scripting (XSS) issue exists in the login page, allowing remote attackers to inject arbitrary web script or HTML via the
GWAP.version parameter. This could potentially lead to unauthorized actions on the affected system.Recommendations
For Novell GroupWise WebAccess versions 6.5 before 20060721, update to a version after 20060721.
For Novell GroupWise WebAccess versions 7 before 20060727, update to a version after 20060727.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Novell Groupwise Webaccess