CVE-2010-2779: XSS
Published Jan 28, 2011
·Updated
Cross-site scripting (XSS) vulnerability in WebAccess in Novell GroupWise 8.x before 8.0 SP2 allows remote attackers to inject arbitrary web script or HTML via a crafted message, related to "replies."
Affected Software
2 affected components
Novell GroupWise=8.0
Novell GroupWise=8.0-sp1
Event History
Jan 28, 2011
CVE Published
via MITRE·09:13 PM
Data Sourced
via MITRE·09:13 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2010-2779?
CVE-2010-2779 has been classified as a medium severity cross-site scripting vulnerability.
2
How do I fix CVE-2010-2779?
The recommended fix for CVE-2010-2779 is to upgrade Novell GroupWise to version 8.0 SP2 or later.
3
What software is affected by CVE-2010-2779?
CVE-2010-2779 affects Novell GroupWise versions 8.0 and 8.0 SP1.
4
What type of vulnerability is CVE-2010-2779?
CVE-2010-2779 is a cross-site scripting (XSS) vulnerability.
5
Can CVE-2010-2779 be exploited remotely?
Yes, CVE-2010-2779 can be exploited remotely by attackers injecting arbitrary web scripts or HTML.