Vulnerability Name:

CVE-2006-4220 (CCN-40215)

Assigned:2006-12-31
Published:2006-12-31
Updated:2011-03-08
Summary:Multiple cross-site scripting (XSS) vulnerabilities in webacc in Novell GroupWise WebAccess before 7 Support Pack 3 Public Beta allow remote attackers to inject arbitrary web script or HTML via the (1) User.html, (2) Error, (3) User.Theme.index, and (4) and User.lang parameters.
CVSS v3 Severity:5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): Low
Availibility (A): None
CVSS v2 Severity:4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N)
3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
4.3 Medium (CCN CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
Vulnerability Type:CWE-79
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2006-4220

Source: CCN
Type: SA28778
Novell GroupWise WebAccess Cross-Site Scripting Vulnerabilities

Source: SECUNIA
Type: Vendor Advisory
28778

Source: CCN
Type: SECTRACK ID: 1019302
GroupWise Input Validation Hole in 'webacc' Permits Cross-Site Scripting Attacks

Source: CCN
Type: Novell Web site, January 31, 2008
GroupWise 7 Support Pack 3 Public Beta

Source: CONFIRM
Type: UNKNOWN
http://www.novell.com/documentation/gw7/readmeusgw7sp3/readmeusgw7sp3.html#b4qb42z

Source: CCN
Type: Novell GroupWise Web site
NOVELL: Novell GroupWise

Source: OSVDB
Type: UNKNOWN
27531

Source: CCN
Type: OSVDB ID: 27531
Novell GroupWise WebAccess webacc Multiple Parameter XSS

Source: BID
Type: UNKNOWN
27582

Source: CCN
Type: BID-27582
Novell GroupWise WebAccess Multiple Cross Site Scripting Vulnerabilities

Source: SECTRACK
Type: UNKNOWN
1019302

Source: VUPEN
Type: UNKNOWN
ADV-2008-0395

Source: XF
Type: UNKNOWN
groupwise-webacc-xss(40215)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:novell:groupwise:5.57e:*:*:*:*:*:*:*
  • OR cpe:/a:novell:groupwise:6.5.7:*:*:*:*:*:*:*
  • OR cpe:/a:novell:groupwise:7.0:*:*:*:*:*:*:*
  • OR cpe:/a:novell:groupwise:7.0.0:sp1:*:*:*:*:*:*
  • OR cpe:/a:novell:groupwise:7.0.0:sp2:*:*:*:*:*:*
  • OR cpe:/a:novell:groupwise_webaccess:*:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:novell:groupwise:7.01:*:*:*:*:*:*:*
  • OR cpe:/a:novell:groupwise:5.57e:*:*:*:*:*:*:*
  • OR cpe:/a:novell:groupwise:6.5.7:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    novell groupwise 5.57e
    novell groupwise 6.5.7
    novell groupwise 7.0
    novell groupwise 7.0.0 sp1
    novell groupwise 7.0.0 sp2
    novell groupwise webaccess *
    novell groupwise 7.01
    novell groupwise 5.57e
    novell groupwise 6.5.7