First published: Sun Dec 31 2006(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in webacc in Novell GroupWise WebAccess before 7 Support Pack 3 Public Beta allow remote attackers to inject arbitrary web script or HTML via the (1) User.html, (2) Error, (3) User.Theme.index, and (4) and User.lang parameters.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Novell GroupWise | =7.0 | |
Novell GroupWise WebAccess | ||
Novell GroupWise | =7.0.0-sp1 | |
Novell GroupWise | =7.0.0-sp2 | |
Novell GroupWise | =5.57e | |
Novell GroupWise | =6.5.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.