Lucene search

K
cve[email protected]CVE-2013-1086
HistoryApr 19, 2013 - 11:44 a.m.

CVE-2013-1086

2013-04-1911:44:23
CWE-79
web.nvd.nist.gov
23
cve-2013-1086
cross-site scripting
xss
novell groupwise
webaccess
html
onerror attribute
nvd

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

5.8 Medium

AI Score

Confidence

High

0.005 Low

EPSS

Percentile

76.8%

Cross-site scripting (XSS) vulnerability in WebAccess in Novell GroupWise before 8.0.3 HP3, and 2012 before SP2, allows remote attackers to inject arbitrary web script or HTML via vectors involving an onError attribute.

Affected configurations

NVD
Node
novellgroupwiseMatch2012
OR
novellgroupwiseMatch2012sp1
OR
novellgroupwiseMatch2012sp1_hp1
Node
novellgroupwiseRange8.03hp2
OR
novellgroupwiseMatch5.2
OR
novellgroupwiseMatch5.5
OR
novellgroupwiseMatch5.57e
OR
novellgroupwiseMatch6.0
OR
novellgroupwiseMatch6.0.1sp1
OR
novellgroupwiseMatch6.5
OR
novellgroupwiseMatch6.5sp1
OR
novellgroupwiseMatch6.5sp2
OR
novellgroupwiseMatch6.5sp3
OR
novellgroupwiseMatch6.5sp4
OR
novellgroupwiseMatch6.5sp5
OR
novellgroupwiseMatch6.5sp6
OR
novellgroupwiseMatch6.5.2
OR
novellgroupwiseMatch6.5.3
OR
novellgroupwiseMatch6.5.4
OR
novellgroupwiseMatch6.5.6
OR
novellgroupwiseMatch6.5.7
OR
novellgroupwiseMatch7.0
OR
novellgroupwiseMatch7.0.3hp4
OR
novellgroupwiseMatch7.0.3hp5
OR
novellgroupwiseMatch7.0.4
OR
novellgroupwiseMatch7.0.4ftf
OR
novellgroupwiseMatch7.01
OR
novellgroupwiseMatch7.01ir1
OR
novellgroupwiseMatch7.02
OR
novellgroupwiseMatch7.02hp1
OR
novellgroupwiseMatch7.02hp1a
OR
novellgroupwiseMatch7.02hp2
OR
novellgroupwiseMatch7.02hp2r1
OR
novellgroupwiseMatch7.03
OR
novellgroupwiseMatch7.03hp
OR
novellgroupwiseMatch7.03hp2
OR
novellgroupwiseMatch7.03hp3
OR
novellgroupwiseMatch7.03hp3\+ftf
OR
novellgroupwiseMatch8.0
OR
novellgroupwiseMatch8.00hp1
OR
novellgroupwiseMatch8.00hp2
OR
novellgroupwiseMatch8.00hp3
OR
novellgroupwiseMatch8.01
OR
novellgroupwiseMatch8.01hp
OR
novellgroupwiseMatch8.02
OR
novellgroupwiseMatch8.02hp1
OR
novellgroupwiseMatch8.02hp2
OR
novellgroupwiseMatch8.02hp3
OR
novellgroupwiseMatch8.03
OR
novellgroupwiseMatch8.03hp1
CPENameOperatorVersion
novell:groupwisenovell groupwiseeq2012

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

5.8 Medium

AI Score

Confidence

High

0.005 Low

EPSS

Percentile

76.8%

Related for CVE-2013-1086