First published: Thu Dec 21 2006(Updated: )
Cross-site scripting (XSS) vulnerability in Novell NetWare 6.5 Support Pack 5 and 6 and Novell Apache on NetWare 2.0.48 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters in Welcome web-app.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache HTTP Server | =2.0.48 | |
Novell NetWare FTP Server | =6.5-sp6 | |
Novell NetWare FTP Server | =6.5-sp5 | |
=2.0.48 | ||
=6.5-sp5 | ||
=6.5-sp6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-6675 is classified as a medium severity vulnerability due to the potential for cross-site scripting attacks.
To fix CVE-2006-6675, upgrade to the latest version of Novell NetWare or Apache HTTP Server that addresses this vulnerability.
CVE-2006-6675 specifically affects Novell NetWare 6.5 Support Pack 5 and 6, as well as Apache HTTP Server version 2.0.48 on NetWare.
CVE-2006-6675 is a cross-site scripting (XSS) vulnerability, allowing remote attackers to inject arbitrary scripts.
Yes, CVE-2006-6675 can potentially lead to data breaches by allowing attackers to execute scripts in the context of a user's browser.