CVE-2006-4220

Novell GroupWise WebAccess - Cross-Site Scripting via User.html, Error, User.Theme.index, and User.lang Parameters

Title source: llm
STIX 2.1

Description

Multiple cross-site scripting (XSS) vulnerabilities in webacc in Novell GroupWise WebAccess before 7 Support Pack 3 Public Beta allow remote attackers to inject arbitrary web script or HTML via the (1) User.html, (2) Error, (3) User.Theme.index, and (4) and User.lang parameters.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Frederic Loudet · textremotenovell
https://www.exploit-db.com/exploits/31095

References (6)

Core 6
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/27582
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1019302
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/27531
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/28778
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/0395

Scores

EPSS 0.0066
EPSS Percentile 71.3%

Details

CWE
CWE-79
Status published
Products (5)
novell/groupwise 5.57e
novell/groupwise 6.5.7
novell/groupwise 7.0
novell/groupwise 7.0.0 sp1 (2 CPE variants)
novell/groupwise_webaccess
Published Dec 31, 2006
Tracked Since Feb 18, 2026