Novell GroupWise WebAccess HTML Injection Vulnerability
BID:14310
Info
Novell GroupWise WebAccess HTML Injection Vulnerability
| Bugtraq ID: | 14310 |
| Class: | Input Validation Error |
| CVE: |
CVE-2005-2276 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 15 2005 12:00AM |
| Updated: | Jul 12 2009 04:06PM |
| Credit: | Discovery is credited to Francisco Amato of Infobyte Security Research. |
| Vulnerable: |
Novell Groupwise 6.5 SP4 Novell Groupwise 6.5 SP3 Novell Groupwise 6.5 SP2 Novell Groupwise 6.5 SP1 Novell Groupwise 6.5 |
| Not Vulnerable: | |
Discussion
Novell GroupWise WebAccess HTML Injection Vulnerability
Novell GroupWise WebAccess is prone to an HTML injection vulnerability. This may be used to inject hostile HTML and script code into the Web mail application. When a user opens an email containing the hostile code, it may be rendered in their browser.
Successful exploitation could potentially allow theft of cookie-based authentication. Other attacks are also possible.
Novell GroupWise WebAccess is prone to an HTML injection vulnerability. This may be used to inject hostile HTML and script code into the Web mail application. When a user opens an email containing the hostile code, it may be rendered in their browser.
Successful exploitation could potentially allow theft of cookie-based authentication. Other attacks are also possible.
Exploit / POC
Novell GroupWise WebAccess HTML Injection Vulnerability
An example email message body was provided:
<IMG SRC="j&#X41vascript:alert(document.cookie)">
An example email message body was provided:
<IMG SRC="j&#X41vascript:alert(document.cookie)">
Solution / Fix
Novell GroupWise WebAccess HTML Injection Vulnerability
Solution:
The vendor has announced that GroupWise releases dated after July 11, 2005 are not affected. Please contact the vendor for information on obtaining an upgraded version. This fix will also be included in Novell GroupWise 6.5 SP5 when it is released.
Solution:
The vendor has announced that GroupWise releases dated after July 11, 2005 are not affected. Please contact the vendor for information on obtaining an upgraded version. This fix will also be included in Novell GroupWise 6.5 SP5 when it is released.
References
Novell GroupWise WebAccess HTML Injection Vulnerability
References:
References: