4.3

CVE-2006-3817

Exploit

Cross-site scripting (XSS) vulnerability in Novell GroupWise WebAccess 6.5 and 7 before 20060727 allows remote attackers to inject arbitrary web script or HTML via an encoded SCRIPT element in an e-mail message with the UTF-7 character set, as demonstrated by the "+ADw-SCRIPT+AD4-" sequence.

Data is provided by the National Vulnerability Database (NVD)
NovellGroupwise Webaccess Version6.5
NovellGroupwise Webaccess Version6.5 Updatesp1
NovellGroupwise Webaccess Version6.5 Updatesp2
NovellGroupwise Webaccess Version6.5 Updatesp3
NovellGroupwise Webaccess Version6.5 Updatesp4
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.66% 0.702
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N