CVE-2006-4220: XSS
Multiple cross-site scripting (XSS) vulnerabilities in webacc in Novell GroupWise WebAccess before 7 Support Pack 3 Public Beta allow remote attackers to inject arbitrary web script or HTML via the (1) User.html, (2) Error, (3) User.Theme.index, and (4) and User.lang parameters.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-4220?
CVE-2006-4220 is considered a medium severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2006-4220?
To fix CVE-2006-4220, update Novell GroupWise WebAccess to version 7 Support Pack 3 or later.
What systems are affected by CVE-2006-4220?
CVE-2006-4220 affects multiple versions of Novell GroupWise WebAccess, particularly those before version 7 Support Pack 3.
What types of vulnerabilities are associated with CVE-2006-4220?
CVE-2006-4220 is associated with multiple cross-site scripting (XSS) vulnerabilities.
Can CVE-2006-4220 lead to data theft?
Yes, CVE-2006-4220 can potentially allow attackers to inject scripts that could lead to data theft from users' browsers.