Cross-Site Scripting Vulnerabilities in Novell Open Enterprise Server
CVE-2009-0611

Currently unrated

Key Information:

Vendor
Novell
Vendor
CVE Published:
17 February 2009

Summary

Multiple cross-site scripting (XSS) vulnerabilities exist in the qfsearch/AdminServlet of Novell Open Enterprise Server 1.x, allowing remote attackers to inject arbitrary web scripts or HTML. This can be achieved through malicious parameters such as 'siteloc' during a displayaddsite action or 'adminurl' in global actions. Exploiting these vulnerabilities can lead to unauthorized access and data manipulation, compromising the security of the affected systems.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.