Novell GroupWise WebAccess Multiple Cross-Site Scripting Vulnerabilities
BID:12310
Info
Novell GroupWise WebAccess Multiple Cross-Site Scripting Vulnerabilities
| Bugtraq ID: | 12310 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 19 2005 12:00AM |
| Updated: | Jan 19 2005 12:00AM |
| Credit: | [email protected] and "Marc Ruef" <maru at scip.ch> are credited with the discovery of these issues. |
| Vulnerable: |
Novell GroupWise WebAccess 6.5 SP2 Novell GroupWise WebAccess 6.5 SP1 Novell GroupWise WebAccess 6.5 Novell GroupWise WebAccess 6.0 SP4 Novell Groupwise 6.5 SP2 Novell Groupwise 6.5 SP1 Novell Groupwise 6.5 Novell Groupwise 6.0 SP4 Novell Groupwise 6.0 SP3 Novell Groupwise 6.0 SP2 Novell Groupwise 6.0 SP1 Novell Groupwise 6.0 |
| Not Vulnerable: | |
Discussion
Novell GroupWise WebAccess Multiple Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting vulnerabilities reportedly affect Novell GroupWise WebAccess. These issues are due to a failure of the application to properly sanitize user-supplied input prior to including it in dynamically generated Web content.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user. This issue may allow for the theft of authentication credentials as well as other attacks.
Multiple cross-site scripting vulnerabilities reportedly affect Novell GroupWise WebAccess. These issues are due to a failure of the application to properly sanitize user-supplied input prior to including it in dynamically generated Web content.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user. This issue may allow for the theft of authentication credentials as well as other attacks.
Exploit / POC
Novell GroupWise WebAccess Multiple Cross-Site Scripting Vulnerabilities
No exploit is required to leverage this issue.
No exploit is required to leverage this issue.
Solution / Fix
Novell GroupWise WebAccess Multiple Cross-Site Scripting Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Novell GroupWise WebAccess Multiple Cross-Site Scripting Vulnerabilities
References:
References:
- Novell GroupWise Homepage (Novell)