Lucene search

K
cveMitreCVE-2006-4220
HistoryFeb 05, 2008 - 11:00 a.m.

CVE-2006-4220

2008-02-0511:00:00
CWE-79
mitre
web.nvd.nist.gov
29
cve-2006-4220
cross-site scripting
xss
vulnerabilities
novell groupwise
webaccess
security
nvd

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

6

Confidence

High

EPSS

0.003

Percentile

71.9%

Multiple cross-site scripting (XSS) vulnerabilities in webacc in Novell GroupWise WebAccess before 7 Support Pack 3 Public Beta allow remote attackers to inject arbitrary web script or HTML via the (1) User.html, (2) Error, (3) User.Theme.index, and (4) and User.lang parameters.

Affected configurations

Nvd
Node
novellgroupwiseMatch5.57e
OR
novellgroupwiseMatch6.5.7
OR
novellgroupwiseMatch7.0
OR
novellgroupwiseMatch7.0.0sp1
OR
novellgroupwiseMatch7.0.0sp2
OR
novellgroupwise_webaccess
VendorProductVersionCPE
novellgroupwise5.57ecpe:2.3:a:novell:groupwise:5.57e:*:*:*:*:*:*:*
novellgroupwise6.5.7cpe:2.3:a:novell:groupwise:6.5.7:*:*:*:*:*:*:*
novellgroupwise7.0cpe:2.3:a:novell:groupwise:7.0:*:*:*:*:*:*:*
novellgroupwise7.0.0cpe:2.3:a:novell:groupwise:7.0.0:sp1:*:*:*:*:*:*
novellgroupwise7.0.0cpe:2.3:a:novell:groupwise:7.0.0:sp2:*:*:*:*:*:*
novellgroupwise_webaccess*cpe:2.3:a:novell:groupwise_webaccess:*:*:*:*:*:*:*:*

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

6

Confidence

High

EPSS

0.003

Percentile

71.9%

Related for CVE-2006-4220