Novell GroupWise 8 WebAccess 'Directory.Item' Parameters Cross-Site Scripting Vulnerabilities
BID:49773
Info
Novell GroupWise 8 WebAccess 'Directory.Item' Parameters Cross-Site Scripting Vulnerabilities
| Bugtraq ID: | 49773 |
| Class: | Input Validation Error |
| CVE: |
CVE-2011-2661 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 26 2011 12:00AM |
| Updated: | Sep 26 2011 12:00AM |
| Credit: | Joshua Tiago |
| Vulnerable: |
Novell Groupwise 8.02 HP2 Novell Groupwise 8.0 SP2 Novell Groupwise 8.0 SP1 Novell Groupwise 8.0 HP2 Novell Groupwise 8.0 HP1 Novell Groupwise 8.0 |
| Not Vulnerable: |
Novell Groupwise 8.02 HP3 |
Discussion
Novell GroupWise 8 WebAccess 'Directory.Item' Parameters Cross-Site Scripting Vulnerabilities
Novell GroupWise is prone to multiple cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker may leverage these issues to execute arbitrary HTML and script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
Groupwise 8.0 up to 8.02HP2 are vulnerable; other versions may also be affected.
Novell GroupWise is prone to multiple cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker may leverage these issues to execute arbitrary HTML and script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
Groupwise 8.0 up to 8.02HP2 are vulnerable; other versions may also be affected.
Exploit / POC
Novell GroupWise 8 WebAccess 'Directory.Item' Parameters Cross-Site Scripting Vulnerabilities
An attacker can exploit these vulnerabilities to execute arbitrary HTML and script code in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and launch other attacks.
An attacker can exploit these vulnerabilities to execute arbitrary HTML and script code in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and launch other attacks.
Solution / Fix
Novell GroupWise 8 WebAccess 'Directory.Item' Parameters Cross-Site Scripting Vulnerabilities
Solution:
Vendor fixes are available. Please see the references for more information.
Solution:
Vendor fixes are available. Please see the references for more information.