CVE-2009-1762: XSS
Multiple cross-site scripting (XSS) vulnerabilities in the WebAccess login page (aka gw/webacc) in Novell GroupWise 7.x before 7.03 HP2 allow remote attackers to inject arbitrary web script or HTML via the (1) GWAP.version or (2) User.Theme (aka User.Theme.index) parameter.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2009-1762?
CVE-2009-1762 has a moderate severity level due to its potential for cross-site scripting attacks.
How do I fix CVE-2009-1762?
To fix CVE-2009-1762, you should upgrade to Novell GroupWise version 7.0.3 HP2 or later.
What types of attacks are possible with CVE-2009-1762?
CVE-2009-1762 allows attackers to perform cross-site scripting attacks via the GWAP.version or User.Theme parameters.
Which versions of Novell GroupWise are affected by CVE-2009-1762?
CVE-2009-1762 affects Novell GroupWise versions prior to 7.03 HP2, including versions 7.0 and 7.0.2.
Can CVE-2009-1762 lead to data theft?
Yes, CVE-2009-1762 can potentially lead to data theft by allowing attackers to execute malicious scripts in the user's browser.