CVE-2011-2224
Novell Data Synchronizer <1.2 - XSS
Title source: llmDescription
The Mobility Pack before 1.2 in Novell Data Synchronizer 1.x through 1.1.2 build 428 does not include the HTTPOnly flag in a Set-Cookie header, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via unspecified vectors.
Scores
EPSS
0.0054
EPSS Percentile
67.4%
Classification
CWE
CWE-79
Status
draft
Affected Products (8)
novell/data_synchronizer
novell/data_synchronizer
novell/data_synchronizer
novell/data_synchronizer
novell/mobility_pack
< 1.1.2
novell/mobility_pack
novell/mobility_pack
novell/mobility_pack
Timeline
Published
Aug 09, 2011
Tracked Since
Feb 18, 2026