Lucene search

K
cve[email protected]CVE-2010-2778
HistoryOct 03, 2022 - 4:21 p.m.

CVE-2010-2778

2022-10-0316:21:08
CWE-79
web.nvd.nist.gov
22
cve
2010
2778
xss
webaccess
novell groupwise
security vulnerability
exploit

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

5.2 Medium

AI Score

Confidence

High

0.005 Low

EPSS

Percentile

75.9%

Cross-site scripting (XSS) vulnerability in WebAccess in Novell GroupWise 7.x before 7.0 post-SP4 FTF and 8.x before 8.0 SP2 allows remote attackers to inject arbitrary web script or HTML via a crafted message, related to a “Javascript XSS exploit.”

Affected configurations

NVD
Node
novellgroupwiseMatch7.0sp1
OR
novellgroupwiseMatch7.0sp2
OR
novellgroupwiseMatch7.0sp3
OR
novellgroupwiseMatch7.0sp4
OR
novellgroupwiseMatch8.0
OR
novellgroupwiseMatch8.0sp1

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

5.2 Medium

AI Score

Confidence

High

0.005 Low

EPSS

Percentile

75.9%

Related for CVE-2010-2778