4.3
CVSSv2

CVE-2005-2276

Published: 26/07/2005 Updated: 11/07/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in Novell Groupwise WebAccess 6.5 before July 11, 2005 allows remote malicious users to inject arbitrary web script or HTML via an e-mail message with an encoded javascript URI (e.g. "j&#X41vascript" in an IMG tag.

Vulnerable Product Search on Vulmon Subscribe to Product

novell groupwise webaccess 6.5

novell groupwise webaccess 6.0

Exploits

source: wwwsecurityfocuscom/bid/14310/info Novell GroupWise WebAccess is prone to an HTML injection vulnerability This may be used to inject hostile HTML and script code into the Web mail application When a user opens an email containing the hostile code, it may be rendered in their browser Successful exploitation could potentially al ...