Cross-site scripting (XSS) vulnerability in Novell GroupWise WebAccess 6.5 and 7 before 20060727 allows remote attackers to inject arbitrary web script or HTML via an encoded SCRIPT element in an e-mail message with the UTF-7 character set, as demonstrated by the "+ADw-SCRIPT+AD4-" sequence.
2006-08-11T10:04:00.000
2025-04-03T01:03:51.193
Deferred
CVSSv2: 4.3 (MEDIUM)
AV:N/AC:M/Au:N/C:N/I:P/A:N
8.6
2.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | novell | groupwise_webaccess | 6.5 | Yes |
| Application | novell | groupwise_webaccess | 6.5 | Yes |
| Application | novell | groupwise_webaccess | 6.5 | Yes |
| Application | novell | groupwise_webaccess | 6.5 | Yes |
| Application | novell | groupwise_webaccess | 6.5 | Yes |
| Application | novell | groupwise_webaccess | 7 | Yes |