CVE-2006-4220
Novell Groupwise - XSS
Title source: ruleDescription
Multiple cross-site scripting (XSS) vulnerabilities in webacc in Novell GroupWise WebAccess before 7 Support Pack 3 Public Beta allow remote attackers to inject arbitrary web script or HTML via the (1) User.html, (2) Error, (3) User.Theme.index, and (4) and User.lang parameters.
Exploits (1)
exploitdb
WRITEUP
VERIFIED
by Frederic Loudet · textremotenovell
https://www.exploit-db.com/exploits/31095
Scores
EPSS
0.0062
EPSS Percentile
69.6%
Classification
CWE
CWE-79
Status
draft
Affected Products (6)
novell/groupwise
novell/groupwise
novell/groupwise
novell/groupwise
novell/groupwise
novell/groupwise_webaccess
Timeline
Published
Dec 31, 2006
Tracked Since
Feb 18, 2026