PT-2006-4676 · Novell · Novell Groupwise Webaccess
Published
2006-08-11
·
Updated
2018-10-17
·
CVE-2006-3817
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Novell GroupWise WebAccess versions prior to 20060727
Description
A cross-site scripting issue allows remote attackers to inject arbitrary web script or HTML via an encoded SCRIPT element in an e-mail message using the UTF-7 character set. This can be achieved with a specific sequence, such as "+ADw-SCRIPT+AD4-".
Recommendations
For Novell GroupWise WebAccess versions prior to 20060727, update to a version released after 20060727 to resolve the issue.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Novell Groupwise Webaccess