Novell GroupWise Client CVE-2013-1087 Cross-Site Scripting Vulnerability
BID:61188
Info
Novell GroupWise Client CVE-2013-1087 Cross-Site Scripting Vulnerability
| Bugtraq ID: | 61188 |
| Class: | Input Validation Error |
| CVE: |
CVE-2013-1087 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 15 2013 12:00AM |
| Updated: | Jul 15 2013 12:00AM |
| Credit: | Bartlomiej Balcerek |
| Vulnerable: |
Novell Groupwise Client 8.03 HP2 Novell Groupwise Client 8.01 Novell Groupwise Client 8.0.3 HP2 Novell Groupwise Client 8.0 Novell Groupwise Client 2012 Novell Groupwise Client 12.01 HP1 |
| Not Vulnerable: |
Novell Groupwise Client 8.0.3 HP3 Novell Groupwise Client 2012 Support Pack 2 |
Discussion
Novell GroupWise Client CVE-2013-1087 Cross-Site Scripting Vulnerability
Novell GroupWise Client is prone to a cross-site scripting vulnerability because it fails to sufficiently sanitize user-supplied input data.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may let the attacker steal cookie-based authentication credentials and launch other attacks.
Versions prior to Novell GroupWise Client 8.0.3 HP3 and 2012 Support Pack 2 are vulnerable.
Novell GroupWise Client is prone to a cross-site scripting vulnerability because it fails to sufficiently sanitize user-supplied input data.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may let the attacker steal cookie-based authentication credentials and launch other attacks.
Versions prior to Novell GroupWise Client 8.0.3 HP3 and 2012 Support Pack 2 are vulnerable.
Exploit / POC
Novell GroupWise Client CVE-2013-1087 Cross-Site Scripting Vulnerability
Attackers can exploit this issue by enticing an unsuspecting user to visit a malicious page.
Attackers can exploit this issue by enticing an unsuspecting user to visit a malicious page.
Solution / Fix
Novell GroupWise Client CVE-2013-1087 Cross-Site Scripting Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Novell GroupWise Client CVE-2013-1087 Cross-Site Scripting Vulnerability
References:
References: