CVE-2005-2276: XSS
Cross-site scripting (XSS) vulnerability in Novell Groupwise WebAccess 6.5 before July 11, 2005 allows remote attackers to inject arbitrary web script or HTML via an e-mail message with an encoded javascript URI (e.g. "jAvascript" in an IMG tag.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2005-2276?
CVE-2005-2276 is considered a medium severity vulnerability due to its potential for exploitation through cross-site scripting.
How do I fix CVE-2005-2276?
To fix CVE-2005-2276, upgrade Novell GroupWise WebAccess to a version released after July 11, 2005.
What type of vulnerability is CVE-2005-2276?
CVE-2005-2276 is a cross-site scripting (XSS) vulnerability that allows remote attackers to inject scripts into web pages.
What software versions are affected by CVE-2005-2276?
CVE-2005-2276 affects Novell GroupWise WebAccess versions 6.5 and earlier, including various service packs.
Can CVE-2005-2276 be exploited through email?
Yes, CVE-2005-2276 can be exploited by sending specially crafted emails that include encoded JavaScript in image tags.