CVE-2006-3817: XSS
Cross-site scripting (XSS) vulnerability in Novell GroupWise WebAccess 6.5 and 7 before 20060727 allows remote attackers to inject arbitrary web script or HTML via an encoded SCRIPT element in an e-mail message with the UTF-7 character set, as demonstrated by the "+ADw-SCRIPT+AD4-" sequence.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-3817?
CVE-2006-3817 is classified as a high severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2006-3817?
To fix CVE-2006-3817, update your Novell GroupWise WebAccess to the latest version or apply any available patches that address this vulnerability.
What versions of Novell GroupWise WebAccess are affected by CVE-2006-3817?
CVE-2006-3817 affects Novell GroupWise WebAccess versions 6.5 and 7 up to and including 20060727.
How does CVE-2006-3817 affect users?
CVE-2006-3817 allows remote attackers to inject arbitrary web scripts into email messages, potentially compromising user sessions.
Can CVE-2006-3817 be exploited remotely?
Yes, CVE-2006-3817 can be exploited remotely by attackers through specially crafted email messages.