Novell GroupWise HTML Injection and Denial of Service Vulnerabilities
BID:28944
Info
Novell GroupWise HTML Injection and Denial of Service Vulnerabilities
| Bugtraq ID: | 28944 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 26 2008 12:00AM |
| Updated: | May 05 2008 06:45PM |
| Credit: | Juan Pablo Lopez Yacubian |
| Vulnerable: |
Novell Groupwise 7.0 |
| Not Vulnerable: |
Novell Groupwise 7.0.0 SP1 |
Discussion
Novell GroupWise HTML Injection and Denial of Service Vulnerabilities
Novell GroupWise is prone to an HTML-injection vulnerability and a denial-of-service vulnerability.
By exploiting the HTML-injection vulnerability, attackers can execute HTML and script code in the context of the affected site, potentially allowing them to steal cookie-based authentication credentials or to control how the site is rendered to the user; other attacks are also possible.
By exploiting the denial-of-service vulnerability, attackers can crash the application.
Novell GroupWise 7 is vulnerable to these issues; other versions may also be affected.
Novell GroupWise is prone to an HTML-injection vulnerability and a denial-of-service vulnerability.
By exploiting the HTML-injection vulnerability, attackers can execute HTML and script code in the context of the affected site, potentially allowing them to steal cookie-based authentication credentials or to control how the site is rendered to the user; other attacks are also possible.
By exploiting the denial-of-service vulnerability, attackers can crash the application.
Novell GroupWise 7 is vulnerable to these issues; other versions may also be affected.
Exploit / POC
Novell GroupWise HTML Injection and Denial of Service Vulnerabilities
The following proof-of-concept exploits are available:
The following proof-of-concept exploits are available:
Solution / Fix
Novell GroupWise HTML Injection and Denial of Service Vulnerabilities
Solution:
The vendor reports that this issue does not affect Groupwise 7.0 SP1 and later. Contact the vendor for more information.
Solution:
The vendor reports that this issue does not affect Groupwise 7.0 SP1 and later. Contact the vendor for more information.
References
Novell GroupWise HTML Injection and Denial of Service Vulnerabilities
References:
References: