Secunia Logo
 
CVE Reference: CVE-2006-3817
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2006-3817

Description:
Cross-site scripting (XSS) vulnerability in Novell GroupWise WebAccess 6.5 and 7 before 20060727 allows remote attackers to inject arbitrary web script or HTML via an encoded SCRIPT element in an e-mail message with the UTF-7 character set, as demonstrated by the "+ADw-SCRIPT+AD4-" sequence.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/28211

ST
  1016648

SAID
  Secunia Advisory: SA21411

MISC
  http://www.infobyte.com.ar/adv/ISR-14.html

FULLDISC
  http://lists.grok.org.uk/pipermail/full-disclosure/2006-August/048593.html

CONFIRM
  http://www.novell.com/support/search.do?cmd=displayKC&externalId=3701584&sliceId=SAL_Public
  http://support.novell.com/cgi-bin/search/searchtid.cgi?/2974176.htm

BUGTRAQ
  http://www.securityfocus.com/archive/1/archive/1/442719/100/100/threaded

BID
  19297


Return to the previous page.