First published: Fri May 11 2007(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in Nokia Intellisync Mobile Suite 6.4.31.2, 6.6.0.107, and 6.6.2.2, possibly involving Novell Groupwise Mobile Server and Nokia Intellisync Wireless Email Express, allow remote attackers to inject arbitrary web script or HTML via the (1) username parameter to de/pda/dev_logon.asp and (2) multiple unspecified vectors in (a) usrmgr/registerAccount.asp, (b) de/create_account.asp, and other files.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Nokia Groupwise Mobile Server | ||
IBM Lotus Notes Intellisync | =6.4.31.2 | |
IBM Lotus Notes Intellisync | =6.6.0.107 | |
IBM Lotus Notes Intellisync | =6.6.2.2 | |
Nokia Intellisync Mobile Suite |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-2592 is considered a medium severity vulnerability due to its potential for cross-site scripting attacks.
To address CVE-2007-2592, ensure you are using the latest patched version of Nokia Intellisync Mobile Suite or any affected software.
CVE-2007-2592 affects Nokia Intellisync Mobile Suite versions 6.4.31.2, 6.6.0.107, and 6.6.2.2, as well as Nokia Groupwise Mobile Server.
CVE-2007-2592 allows attackers to execute arbitrary web scripts or HTML via cross-site scripting.
Remote attackers can exploit CVE-2007-2592 to inject malicious scripts into the affected software.