First published: Sat Oct 08 2011(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in WebAccess in Novell GroupWise 8.0 before HP3 allow remote attackers to inject arbitrary web script or HTML via the (1) Directory.Item.name or (2) Directory.Item.displayName parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Micro Focus GroupWise | =8.0 | |
Micro Focus GroupWise | =8.0-hp1 | |
Micro Focus GroupWise | =8.0-hp2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-2661 is classified as a high severity vulnerability due to its potential for exploitation via remote cross-site scripting attacks.
To fix CVE-2011-2661, upgrade Novell GroupWise to version 8.0 HP3 or later to mitigate the XSS vulnerabilities.
CVE-2011-2661 affects Novell GroupWise versions 8.0, 8.0 HP1, and 8.0 HP2.
Attackers can exploit CVE-2011-2661 by injecting malicious web scripts through the Directory.Item.name or Directory.Item.displayName parameters.
Exploitation of CVE-2011-2661 can lead to unauthorized execution of scripts in users' browsers, potentially resulting in data theft or session hijacking.