CVE-2011-2661: XSS
Multiple cross-site scripting (XSS) vulnerabilities in WebAccess in Novell GroupWise 8.0 before HP3 allow remote attackers to inject arbitrary web script or HTML via the (1) Directory.Item.name or (2) Directory.Item.displayName parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-2661?
CVE-2011-2661 is classified as a high severity vulnerability due to its potential for exploitation via remote cross-site scripting attacks.
How do I fix CVE-2011-2661?
To fix CVE-2011-2661, upgrade Novell GroupWise to version 8.0 HP3 or later to mitigate the XSS vulnerabilities.
Which versions of Novell GroupWise are affected by CVE-2011-2661?
CVE-2011-2661 affects Novell GroupWise versions 8.0, 8.0 HP1, and 8.0 HP2.
What are the common attack vectors for CVE-2011-2661?
Attackers can exploit CVE-2011-2661 by injecting malicious web scripts through the Directory.Item.name or Directory.Item.displayName parameters.
What impact can CVE-2011-2661 have on an organization?
Exploitation of CVE-2011-2661 can lead to unauthorized execution of scripts in users' browsers, potentially resulting in data theft or session hijacking.