Cross-Site Scripting Vulnerability in Novell GroupWise WebAccess
CVE-2006-3818

Currently unrated

Key Information:

Vendor

Novell

Vendor
CVE Published:
11 August 2006

What is CVE-2006-3818?

A Cross-site Scripting (XSS) vulnerability exists within the login page of Novell GroupWise WebAccess prior to specific versions, allowing remote attackers to inject arbitrary web scripts or HTML through the GWAP.version parameter. This vulnerability can potentially compromise the security of user sessions, facilitate phishing attacks, or enable unauthorized access to sensitive information within the application.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.