Novell GroupWise Multiple HTML Injection Scripting Vulnerabilities
BID:19297
CVE-2006-3817 | CVE-2006-3818 |Info
Novell GroupWise Multiple HTML Injection Scripting Vulnerabilities
| Bugtraq ID: | 19297 |
| Class: | Input Validation Error |
| CVE: |
CVE-2006-3817 CVE-2006-3818 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 28 2006 12:00AM |
| Updated: | Sep 05 2006 10:43PM |
| Credit: | Jerome Odegaard and Francisco Amato are credited with the discovery of these vulnerabilities. |
| Vulnerable: |
Novell Groupwise 6.5.4 Novell Groupwise 6.5.3 Novell Groupwise 6.5.2 Novell Groupwise 6.5 SP6 Update 1 Novell Groupwise 6.5 SP6 Novell Groupwise 6.5 SP5 Novell Groupwise 6.5 SP4 Novell Groupwise 6.5 SP3 Novell Groupwise 6.5 SP2 Novell Groupwise 6.5 SP1 Novell Groupwise 6.5 Novell Groupwise 6.0 SP4 Novell Groupwise 6.0 SP3 Novell Groupwise 6.0 SP2 Novell Groupwise 6.0 SP1 Novell Groupwise 6.0 |
| Not Vulnerable: |
Novell Groupwise 6.5 Post SP6 |
Discussion
Novell GroupWise Multiple HTML Injection Scripting Vulnerabilities
Novell GroupWise is prone to multiple HTML-injection vulnerabilities.
These issues occur because the application fails to sanitize user-input before using dynamically generated content.
An attacker may leverage these issues to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
Novell GroupWise is prone to multiple HTML-injection vulnerabilities.
These issues occur because the application fails to sanitize user-input before using dynamically generated content.
An attacker may leverage these issues to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
Exploit / POC
Novell GroupWise Multiple HTML Injection Scripting Vulnerabilities
Attackers can exploit this issue via a web client.
Attackers can exploit this issue via a web client.
Solution / Fix
Novell GroupWise Multiple HTML Injection Scripting Vulnerabilities
Solution:
The vendor has released updates to address these issues. Please see the references for more information.
Solution:
The vendor has released updates to address these issues. Please see the references for more information.
References
Novell GroupWise Multiple HTML Injection Scripting Vulnerabilities
References:
References:
- FTF: GroupWise 6.5 Post SP6 WebAccess Rev D - TID2974176 (Novell)
- Vendor Web Page (Novell)