Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Novell GroupWise WebAccess HTML Injection Vulnerability

Novell GroupWise WebAccess is prone to an HTML injection vulnerability. This may be used to inject hostile HTML and script code into the Web mail application. When a user opens an email containing the hostile code, it may be rendered in their browser.

Successful exploitation could potentially allow theft of cookie-based authentication. Other attacks are also possible.







 

Privacy Statement
Copyright 2008, SecurityFocus