PT-2006-4676 · Novell · Novell Groupwise Webaccess

Published

2006-08-11

·

Updated

2018-10-17

·

CVE-2006-3817

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Novell GroupWise WebAccess versions prior to 20060727
Description A cross-site scripting issue allows remote attackers to inject arbitrary web script or HTML via an encoded SCRIPT element in an e-mail message using the UTF-7 character set. This can be achieved with a specific sequence, such as "+ADw-SCRIPT+AD4-".
Recommendations For Novell GroupWise WebAccess versions prior to 20060727, update to a version released after 20060727 to resolve the issue.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-3817

Affected Products

Novell Groupwise Webaccess