First published: Fri Aug 11 2006(Updated: )
Cross-site scripting (XSS) vulnerability in the login page in Novell GroupWise WebAccess 6.5 before 20060721 and WebAccess 7 before 20060727 allows remote attackers to inject arbitrary web script or HTML via the GWAP.version parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Novell GroupWise WebAccess | =7 | |
Novell GroupWise WebAccess | =6.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-3818 has been classified as a medium severity vulnerability due to the risk of cross-site scripting attacks.
To fix CVE-2006-3818, upgrade Novell GroupWise WebAccess to versions 6.5 after 20060721 or 7 after 20060727.
CVE-2006-3818 allows attackers to perform cross-site scripting attacks by injecting malicious web scripts into the login page.
CVE-2006-3818 affects Novell GroupWise WebAccess versions 6.5 before 20060721 and 7 before 20060727.
Yes, user data may be at risk with CVE-2006-3818 if attackers successfully execute cross-site scripting, potentially stealing session cookies or credentials.