Lucene search

K
zdiScriptjunkie scriptjunkie1 {nospam} googlemail {nospam} comZDI-10-135
HistoryJul 20, 2010 - 12:00 a.m.

Novell Groupwise WebAccess Multiple Cross-Site Scripting Vulnerabilities

2010-07-2000:00:00
scriptjunkie scriptjunkie1 {nospam} googlemail {nospam} com
www.zerodayinitiative.com
15

0.005 Low

EPSS

Percentile

75.9%

This vulnerability allows remote attackers to execute arbitrary client side script on vulnerable installations of Novell Groupwise WebAccess. Authentication is notrequired to exploit this vulnerability. The specific flaw exists within handling html messages sent to a Novell GroupwiseWebAccess user. Messages are improperly sanitized allowing client side script to be supplied to the user’s web browser resulting in the user’s WebAccess credentialsbeing compromised.

0.005 Low

EPSS

Percentile

75.9%

Related for ZDI-10-135