Novell GroupWise WebAccess Unspecified HTML Injection Vulnerability
BID:33537
Info
Novell GroupWise WebAccess Unspecified HTML Injection Vulnerability
| Bugtraq ID: | 33537 |
| Class: | Input Validation Error |
| CVE: |
CVE-2009-0273 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 30 2009 12:00AM |
| Updated: | Jan 30 2009 07:09PM |
| Credit: | Jan Fry of ProCheckUp Ltd |
| Vulnerable: |
Novell GroupWise WebAccess 6.5 SP2 Novell GroupWise WebAccess 6.5 SP1 Novell GroupWise WebAccess 6.5 Novell Groupwise 7.0 Novell Groupwise 8.0 Novell Groupwise 7.03HP1a Novell Groupwise 7.03 Novell Groupwise 7.02x Novell Groupwise 7.01 Novell Groupwise 7.0.0 SP3 Novell Groupwise 7.0.0 SP2 Novell Groupwise 7.0.0 SP1 |
| Not Vulnerable: |
Novell Groupwise 8.0 HP1 Novell Groupwise 7.03 HP2 |
Discussion
Novell GroupWise WebAccess Unspecified HTML Injection Vulnerability
Novell GroupWise WebAccess is prone to an HTML-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.
Novell GroupWise WebAccess is prone to an HTML-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.
Exploit / POC
Novell GroupWise WebAccess Unspecified HTML Injection Vulnerability
Attackers can use a browser to exploit this issue.
Attackers can use a browser to exploit this issue.
Solution / Fix
Novell GroupWise WebAccess Unspecified HTML Injection Vulnerability
Solution:
The vendor has released updates. Please contact the vendor for details.
Solution:
The vendor has released updates. Please contact the vendor for details.
References
Novell GroupWise WebAccess Unspecified HTML Injection Vulnerability
References:
References:
- Novell GroupWise Homepage (Novell)
- PR08-22: Persistent XSS on Novell GroupWise WebAccess (ProCheckUp Research
) - 7002320 Persistent Cross-site Scripting (XSS) Security Vulnerability with GroupW (Novell)