PT-2006-7277 · Novell · Novell Netware+1
Published
2006-12-21
·
Updated
2016-12-06
·
CVE-2006-6675
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
Novell NetWare versions 6.5 Support Pack 5 and 6
Novell Apache on NetWare version 2.0.48
Description:
A cross-site scripting (XSS) issue allows remote attackers to inject arbitrary web script or HTML via unspecified parameters in the Welcome web-app. This could potentially lead to unauthorized actions on the affected system.
Recommendations:
For Novell NetWare versions 6.5 Support Pack 5 and 6, update to a version that includes the fix for this issue.
For Novell Apache on NetWare version 2.0.48, update to a version that includes the fix for this issue.
As a temporary workaround, consider restricting access to the Welcome web-app until a patch is available.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Novell Apache On Netware
Novell Netware