4.3

CVE-2005-2276

Exploit

Cross-site scripting (XSS) vulnerability in Novell Groupwise WebAccess 6.5 before July 11, 2005 allows remote attackers to inject arbitrary web script or HTML via an e-mail message with an encoded javascript URI (e.g. "j&#X41vascript" in an IMG tag.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
NovellGroupwise Webaccess Version6.0 Updatesp4
NovellGroupwise Webaccess Version6.5
NovellGroupwise Webaccess Version6.5 Updatesp1
NovellGroupwise Webaccess Version6.5 Updatesp2
NovellGroupwise Webaccess Version6.5 Updatesp3
NovellGroupwise Webaccess Version6.5 Updatesp4
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.46% 0.8
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N