vendor:
GroupWise WebAccess
by:
SecurityFocus
7.5
CVSS
HIGH
HTML Injection
79
CWE
Product Name: GroupWise WebAccess
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2005
Novell GroupWise WebAccess HTML Injection Vulnerability
Novell GroupWise WebAccess is prone to an HTML injection vulnerability. This may be used to inject hostile HTML and script code into the Web mail application. When a user opens an email containing the hostile code, it may be rendered in their browser. Successful exploitation could potentially allow theft of cookie-based authentication. Other attacks are also possible.
Mitigation:
Input validation should be used to prevent hostile HTML and script code from being injected into the application.