Vulnerability Name: | CVE-2009-4662 (CCN-53322) | ||||||||
Assigned: | 2009-09-16 | ||||||||
Published: | 2009-09-16 | ||||||||
Updated: | 2017-08-17 | ||||||||
Summary: | Cross-site scripting (XSS) vulnerability in the WebAccess component in Novell GroupWise 7.0 before 7.03 HP4 and 8.0 before 8.0 SP1 allows remote attackers to inject arbitrary web script or HTML via the User.Theme.index parameter. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N) 3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-79 | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2009-4662 Source: CCN Type: SA36746 Novell GroupWise WebAccess "User.Theme.index" Cross-Site Scripting Source: SECUNIA Type: Vendor Advisory 36746 Source: CCN Type: SECTRACK ID: 1022910 Novell GroupWise WebAccess Input Validation Hole in 'User.Theme.index' Parameter Permits Cross-Site Scripting Attacks Source: CCN Type: Novell Document ID: 7004410 GroupWise WebAccess - Cross Site Scripting (XSS) Security Vulnerability in User.Theme.index parameter Source: CONFIRM Type: Vendor Advisory http://www.novell.com/support/viewContent.do?externalId=7004410&sliceId=1 Source: CCN Type: OSVDB ID: 58167 Novell GroupWise WebAccess User.Theme.index Parameter XSS Source: BID Type: UNKNOWN 36437 Source: CCN Type: BID-36437 Novell GroupWise WebAccess Cross-Site Scripting Vulnerability Source: SECTRACK Type: UNKNOWN 1022910 Source: VUPEN Type: Vendor Advisory ADV-2009-2689 Source: XF Type: UNKNOWN groupwise-webaccess-userthemeindex-xss(53322) Source: XF Type: UNKNOWN groupwise-webaccess-userthemeindex-xss(53322) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |