PT-2006-4677 · Novell · Novell Groupwise Webaccess

Published

2006-08-11

·

Updated

2018-10-17

·

CVE-2006-3818

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Novell GroupWise WebAccess versions 6.5 before 20060721 Novell GroupWise WebAccess versions 7 before 20060727
Description A cross-site scripting (XSS) issue exists in the login page, allowing remote attackers to inject arbitrary web script or HTML via the GWAP.version parameter. This could potentially lead to unauthorized actions on the affected system.
Recommendations For Novell GroupWise WebAccess versions 6.5 before 20060721, update to a version after 20060721. For Novell GroupWise WebAccess versions 7 before 20060727, update to a version after 20060727.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-3818

Affected Products

Novell Groupwise Webaccess