Vulnerability Name: | CVE-2009-1635 (CCN-50689) | ||||||||
Assigned: | 2009-05-14 | ||||||||
Published: | 2009-05-14 | ||||||||
Updated: | 2018-10-10 | ||||||||
Summary: | Multiple cross-site scripting (XSS) vulnerabilities in the WebAccess component in Novell GroupWise 7.x before 7.03 HP3 and 8.x before 8.0 HP2 allow remote attackers to inject arbitrary web script or HTML via (1) the User.lang parameter to the login page (aka gw/webacc), (2) style expressions in a message that contains an HTML file, or (3) vectors associated with incorrect protection mechanisms against scripting, as demonstrated using whitespace between JavaScript event names and values. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N) 3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-79 | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2009-1635 Source: MISC Type: UNKNOWN http://packetstorm.linuxsecurity.com/0905-exploits/groupwise-xss.txt Source: CCN Type: SA35177 Novell GroupWise Multiple Vulnerabilities Source: SECUNIA Type: UNKNOWN 35177 Source: CCN Type: SECTRACK ID: 1022267 Novell GroupWise WebAccess Input Validation Flaw in Login Page Permits Cross-Site Scripting Attacks Source: SECTRACK Type: UNKNOWN 1022267 Source: CONFIRM Type: Patch, Vendor Advisory http://www.novell.com/support/search.do?cmd=displayKC&externalId=7003271 Source: CCN Type: Novell Document ID: 7003267 Novell GroupWise WebAccess - Cross Site Scripting (XSS) Security Vulnerability via Unfiltered Style Expressions Source: CONFIRM Type: UNKNOWN http://www.novell.com/support/viewContent.do?externalId=7003267&sliceId=1 Source: CONFIRM Type: UNKNOWN http://www.novell.com/support/viewContent.do?externalId=7003268&sliceId=1 Source: BUGTRAQ Type: UNKNOWN 20090521 Novell GroupWise Web Access Multiple XSS Source: BUGTRAQ Type: UNKNOWN 20090528 Novell Groupwise fails to properly sanitize emails. Source: BID Type: UNKNOWN 35061 Source: CCN Type: BID-35061 Novell GroupWise WebAccess 'gw/webacc' Multiple Cross-Site Scripting Vulnerabilities Source: BID Type: UNKNOWN 35066 Source: CCN Type: BID-35066 Novell GroupWise WebAccess Multiple Security Vulnerabilities Source: VUPEN Type: UNKNOWN ADV-2009-1393 Source: MISC Type: UNKNOWN https://bugzilla.novell.com/show_bug.cgi?id=472987 Source: MISC Type: UNKNOWN https://bugzilla.novell.com/show_bug.cgi?id=474500 Source: MISC Type: UNKNOWN https://bugzilla.novell.com/show_bug.cgi?id=484942 Source: XF Type: UNKNOWN groupwise-webaccess-loginpage-xss(50672) Source: XF Type: UNKNOWN groupwise-styleexpressions-xss(50689) Source: XF Type: UNKNOWN groupwise-styleexpressions-xss(50689) Source: XF Type: UNKNOWN groupwise-unspecified-xss(50691) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
Vulnerability Name: | CVE-2009-1635 (CCN-50691) | ||||||||
Assigned: | 2009-05-14 | ||||||||
Published: | 2009-05-14 | ||||||||
Updated: | 2018-10-10 | ||||||||
Summary: | Multiple cross-site scripting (XSS) vulnerabilities in the WebAccess component in Novell GroupWise 7.x before 7.03 HP3 and 8.x before 8.0 HP2 allow remote attackers to inject arbitrary web script or HTML via (1) the User.lang parameter to the login page (aka gw/webacc), (2) style expressions in a message that contains an HTML file, or (3) vectors associated with incorrect protection mechanisms against scripting, as demonstrated using whitespace between JavaScript event names and values. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N) 3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-79 | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2009-1635 Source: CCN Type: SA35177 Novell GroupWise Multiple Vulnerabilities Source: CCN Type: SECTRACK ID: 1022267 Novell GroupWise WebAccess Input Validation Flaw in Login Page Permits Cross-Site Scripting Attacks Source: CCN Type: Novell Document ID: 7003268 Novell GroupWise WebAccess - Scripting Security Vulnerability Source: CCN Type: BID-35061 Novell GroupWise WebAccess 'gw/webacc' Multiple Cross-Site Scripting Vulnerabilities Source: CCN Type: BID-35066 Novell GroupWise WebAccess Multiple Security Vulnerabilities Source: XF Type: UNKNOWN groupwise-unspecified-xss(50691) | ||||||||
BACK |