CVE-2012-0272: XSS
Cross-site scripting (XSS) vulnerability in the WebAccess component in Novell GroupWise 8.0 before Support Pack 3 allows remote attackers to inject arbitrary web script or HTML via the merge parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-0272?
CVE-2012-0272 has a medium severity rating as it allows remote attackers to execute arbitrary web scripts or HTML via the merge parameter.
How do I fix CVE-2012-0272?
To fix CVE-2012-0272, users should upgrade to Novell GroupWise 8.0 Support Pack 3 or later.
What software is affected by CVE-2012-0272?
CVE-2012-0272 affects Novell GroupWise version 8.0 and its subsequent hotfix versions before Support Pack 3.
How does CVE-2012-0272 exploit vulnerabilities in Novell GroupWise?
CVE-2012-0272 exploits a cross-site scripting vulnerability that allows injection of arbitrary web scripts through a vulnerable parameter.
Can CVE-2012-0272 be exploited remotely?
Yes, CVE-2012-0272 can be exploited remotely by attackers targeting the WebAccess component of Novell GroupWise.