Vulnerability Name:

CVE-2006-3817 (CCN-28211)

Assigned:2006-07-28
Published:2006-07-28
Updated:2018-10-17
Summary:Cross-site scripting (XSS) vulnerability in Novell GroupWise WebAccess 6.5 and 7 before 20060727 allows remote attackers to inject arbitrary web script or HTML via an encoded SCRIPT element in an e-mail message with the UTF-7 character set, as demonstrated by the "+ADw-SCRIPT+AD4-" sequence.
This vulnerability is addressed in the following product update:
Novell, GroupWise WebAccess, 6.5 20060727
Novell, GroupWise WebAccess, 7 20060727
CVSS v3 Severity:4.8 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): High
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): None
CVSS v2 Severity:4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N)
3.2 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
4.0 Medium (CCN CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:N)
3.0 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:N/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): High
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): None
Vulnerability Type:CWE-Other
Vulnerability Consequences:Gain Access
References:Source: CCN
Type: Full-Disclosure Mailing List, Tue Aug 08 2006 - 14:43:26 CDT
[ISR] - Novell Groupwise Webaccess (Cross-Site Scripting)

Source: MITRE
Type: CNA
CVE-2006-3817

Source: FULLDISC
Type: Exploit, Patch
20060808 [ISR] - Novell Groupwise Webaccess (Cross-Site Scripting)

Source: CCN
Type: SA21411
Novell GroupWise WebAccess Multiple Vulnerabilities

Source: SECUNIA
Type: Exploit, Patch, Vendor Advisory
21411

Source: CCN
Type: SECTRACK ID: 1016648
GroupWise WebAccess Input Validation Holes in the Login Page and Other Pages Permit Cross-Site Scripting Attacks

Source: SECTRACK
Type: UNKNOWN
1016648

Source: CCN
Type: Novell Technical Information Document TID2974176
FTF: GroupWise 6.5 Post SP6 WebAccess Rev D

Source: CONFIRM
Type: Patch
http://support.novell.com/cgi-bin/search/searchtid.cgi?/2974176.htm

Source: MISC
Type: Exploit, Patch
http://www.infobyte.com.ar/adv/ISR-14.html

Source: CCN
Type: Novell GroupWise Web site
NOVELL: Novell GroupWise

Source: CONFIRM
Type: Patch
http://www.novell.com/support/search.do?cmd=displayKC&externalId=3701584&sliceId=SAL_Public

Source: CCN
Type: OSVDB ID: 27818
Novell GroupWise WebAccess UTF-7 Encoded Message XSS

Source: CCN
Type: OSVDB ID: 27819
Novell GroupWise WebAccess Malformed SCRIPT Tag XSS

Source: BUGTRAQ
Type: UNKNOWN
20060808 [ISR] - Novell Groupwise Webaccess (Cross-Site Scripting)

Source: BID
Type: UNKNOWN
19297

Source: CCN
Type: BID-19297
Novell GroupWise Multiple HTML Injection Scripting Vulnerabilities

Source: VUPEN
Type: UNKNOWN
ADV-2006-3098

Source: XF
Type: UNKNOWN
groupwise-utf7-xss(28211)

Source: XF
Type: UNKNOWN
groupwise-utf7-xss(28211)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:novell:groupwise_webaccess:6.5:*:*:*:*:*:*:*
  • OR cpe:/a:novell:groupwise_webaccess:6.5:sp1:*:*:*:*:*:*
  • OR cpe:/a:novell:groupwise_webaccess:6.5:sp2:*:*:*:*:*:*
  • OR cpe:/a:novell:groupwise_webaccess:6.5:sp3:*:*:*:*:*:*
  • OR cpe:/a:novell:groupwise_webaccess:6.5:sp4:*:*:*:*:*:*
  • OR cpe:/a:novell:groupwise_webaccess:7:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:novell:groupwise_webaccess:6.5:*:*:*:*:*:*:*
  • OR cpe:/a:novell:groupwise:6.5:sp1:*:*:*:*:*:*
  • OR cpe:/a:novell:groupwise:6.5:sp2:*:*:*:*:*:*
  • OR cpe:/a:novell:groupwise:6.5:sp3:*:*:*:*:*:*
  • OR cpe:/a:novell:groupwise:6.5:sp4:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    novell groupwise webaccess 6.5
    novell groupwise webaccess 6.5 sp1
    novell groupwise webaccess 6.5 sp2
    novell groupwise webaccess 6.5 sp3
    novell groupwise webaccess 6.5 sp4
    novell groupwise webaccess 7
    novell groupwise webaccess 6.5
    novell groupwise 6.5 sp1
    novell groupwise 6.5 sp2
    novell groupwise 6.5 sp3
    novell groupwise 6.5 sp4