CVE-2006-4220
Novell GroupWise WebAccess - Cross-Site Scripting via User.html, Error, User.Theme.index, and User.lang Parameters
Title source: llmDescription
Multiple cross-site scripting (XSS) vulnerabilities in webacc in Novell GroupWise WebAccess before 7 Support Pack 3 Public Beta allow remote attackers to inject arbitrary web script or HTML via the (1) User.html, (2) Error, (3) User.Theme.index, and (4) and User.lang parameters.
Exploits (1)
exploitdb
WRITEUP
VERIFIED
by Frederic Loudet · textremotenovell
https://www.exploit-db.com/exploits/31095
References (6)
Core 6
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/27582
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id?1019302
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://www.osvdb.org/27531
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/28778
Third Party Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2008/0395
Vendor Advisory x_refsource_confirm
http://www.novell.com/documentation/gw7/readmeusgw7sp3/readmeusgw7sp3.html#b4qb42z
Scores
EPSS
0.0066
EPSS Percentile
71.3%
Details
CWE
CWE-79
Status
published
Products (5)
novell/groupwise
5.57e
novell/groupwise
6.5.7
novell/groupwise
7.0
novell/groupwise
7.0.0 sp1 (2 CPE variants)
novell/groupwise_webaccess
Published
Dec 31, 2006
Tracked Since
Feb 18, 2026