CVE-2006-3818: XSS
Cross-site scripting (XSS) vulnerability in the login page in Novell GroupWise WebAccess 6.5 before 20060721 and WebAccess 7 before 20060727 allows remote attackers to inject arbitrary web script or HTML via the GWAP.version parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-3818?
CVE-2006-3818 has been classified as a medium severity vulnerability due to the risk of cross-site scripting attacks.
How do I fix CVE-2006-3818?
To fix CVE-2006-3818, upgrade Novell GroupWise WebAccess to versions 6.5 after 20060721 or 7 after 20060727.
What types of attacks are possible with CVE-2006-3818?
CVE-2006-3818 allows attackers to perform cross-site scripting attacks by injecting malicious web scripts into the login page.
What versions of Novell GroupWise WebAccess are affected by CVE-2006-3818?
CVE-2006-3818 affects Novell GroupWise WebAccess versions 6.5 before 20060721 and 7 before 20060727.
Is user data at risk with CVE-2006-3818?
Yes, user data may be at risk with CVE-2006-3818 if attackers successfully execute cross-site scripting, potentially stealing session cookies or credentials.