First published: Sun Dec 31 2006(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in webacc in Novell GroupWise WebAccess before 7 Support Pack 3 Public Beta allow remote attackers to inject arbitrary web script or HTML via the (1) User.html, (2) Error, (3) User.Theme.index, and (4) and User.lang parameters.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Novell GroupWise | =7.0 | |
Novell GroupWise WebAccess | ||
Novell GroupWise | =7.0.0-sp1 | |
Novell GroupWise | =7.0.0-sp2 | |
Novell GroupWise | =5.57e | |
Novell GroupWise | =6.5.7 | |
=5.57e | ||
=6.5.7 | ||
=7.0 | ||
=7.0.0-sp1 | ||
=7.0.0-sp2 | ||
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-4220 is considered a medium severity vulnerability due to its potential for cross-site scripting attacks.
To fix CVE-2006-4220, update Novell GroupWise WebAccess to version 7 Support Pack 3 or later.
CVE-2006-4220 affects multiple versions of Novell GroupWise WebAccess, particularly those before version 7 Support Pack 3.
CVE-2006-4220 is associated with multiple cross-site scripting (XSS) vulnerabilities.
Yes, CVE-2006-4220 can potentially allow attackers to inject scripts that could lead to data theft from users' browsers.