First published: Tue Jul 26 2005(Updated: )
Cross-site scripting (XSS) vulnerability in Novell Groupwise WebAccess 6.5 before July 11, 2005 allows remote attackers to inject arbitrary web script or HTML via an e-mail message with an encoded javascript URI (e.g. "jAvascript" in an IMG tag.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Novell GroupWise WebAccess | =6.5 | |
Novell GroupWise WebAccess | =6.5-sp1 | |
Novell GroupWise WebAccess | =6.5-sp4 | |
Novell GroupWise WebAccess | =6.5-sp2 | |
Novell GroupWise WebAccess | =6.0-sp4 | |
Novell GroupWise WebAccess | =6.5-sp3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-2276 is considered a medium severity vulnerability due to its potential for exploitation through cross-site scripting.
To fix CVE-2005-2276, upgrade Novell GroupWise WebAccess to a version released after July 11, 2005.
CVE-2005-2276 is a cross-site scripting (XSS) vulnerability that allows remote attackers to inject scripts into web pages.
CVE-2005-2276 affects Novell GroupWise WebAccess versions 6.5 and earlier, including various service packs.
Yes, CVE-2005-2276 can be exploited by sending specially crafted emails that include encoded JavaScript in image tags.