CVE-2009-1762
Novell GroupWise 7.x < 7.03 HP2 - Cross-Site Scripting via WebAccess Login Page Parameters
Title source: llmDescription
Multiple cross-site scripting (XSS) vulnerabilities in the WebAccess login page (aka gw/webacc) in Novell GroupWise 7.x before 7.03 HP2 allow remote attackers to inject arbitrary web script or HTML via the (1) GWAP.version or (2) User.Theme (aka User.Theme.index) parameter.
References (8)
Core 8
Core References
Third Party Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2009/1393
Issue Tracking x_refsource_misc
https://bugzilla.novell.com/show_bug.cgi?id=484942
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/35177
Various Sources x_refsource_misc
http://packetstorm.linuxsecurity.com/0905-exploits/groupwise-xss.txt
Patch, Vendor Advisory x_refsource_confirm
http://www.novell.com/support/search.do?cmd=displayKC&externalId=7003271
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/35061
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://securitytracker.com/id?1022267
Third Party Advisory, VDB Entry mailing-list
x_refsource_bugtraq
http://www.securityfocus.com/archive/1/503700/100/0/threaded
Scores
EPSS
0.0157
EPSS Percentile
81.7%
Details
CWE
CWE-79
Status
published
Products (7)
novell/groupwise
7.0 (4 CPE variants)
novell/groupwise
7.0.0 sp1 (2 CPE variants)
novell/groupwise
7.0.2
novell/groupwise
7.0.3
novell/groupwise
7.01
novell/groupwise
7.02x
novell/groupwise
7.03 (3 CPE variants)
Published
May 22, 2009
Tracked Since
Feb 18, 2026