PT-2005-3204 · Novell · Novell Groupwise Webaccess
Francisco Amato
·
Published
2005-07-26
·
Updated
2017-07-11
·
CVE-2005-2276
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions:
Novell Groupwise WebAccess version 6.5
Description:
A cross-site scripting issue allows remote attackers to inject arbitrary web script or HTML via an e-mail message with an encoded javascript URI, such as "jAvascript" in an IMG tag.
Recommendations:
For Novell Groupwise WebAccess version 6.5, update to a version released after July 11, 2005 to resolve the issue.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Novell Groupwise Webaccess