Vulnerabilities > CVE-2006-3817 - HTML Injection Scripting vulnerability in Novell Groupwise Webaccess 6.5/7

047910
CVSS 4.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
novell

Summary

Cross-site scripting (XSS) vulnerability in Novell GroupWise WebAccess 6.5 and 7 before 20060727 allows remote attackers to inject arbitrary web script or HTML via an encoded SCRIPT element in an e-mail message with the UTF-7 character set, as demonstrated by the "+ADw-SCRIPT+AD4-" sequence. This vulnerability is addressed in the following product update: Novell, GroupWise WebAccess, 6.5 20060727 Novell, GroupWise WebAccess, 7 20060727

Vulnerable Configurations

Part Description Count
Application
Novell
6