CVE-2004-2103
published 2004-12-31CVE-2004-2103: Cross-site scripting (XSS) vulnerability in Novell NetWare Enterprise Web Server 5.1 and 6.0 allows remote attackers to process arbitrary script or HTML as…
PriorityP416medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
2.09%
79.4th percentile
Cross-site scripting (XSS) vulnerability in Novell NetWare Enterprise Web Server 5.1 and 6.0 allows remote attackers to process arbitrary script or HTML as other users via (1) a malformed request for a Perl program with script in the filename, (2) the User.id parameter to the webacc servlet, (3) the GWAP.version parameter to webacc, or (4) a URL request for a .bas file with script in the filename.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| novell | groupwise_webaccess | — | — |
| novell | netware | — | — |
| novell | netware | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-ww39-q3qc-xp7c: Cross-site scripting (XSS) vulnerability in the webacc servlet in Novell GroupWise 6
ghsa_unreviewed·2022-05-01·CVSS 4.3
CVE-2007-4557 [MEDIUM] CWE-79 GHSA-ww39-q3qc-xp7c: Cross-site scripting (XSS) vulnerability in the webacc servlet in Novell GroupWise 6
Cross-site scripting (XSS) vulnerability in the webacc servlet in Novell GroupWise 6.5 WebAccess allows remote attackers to inject arbitrary web script or HTML via the User.Id parameter, as demonstrated by a URL within a url field in a STYLE element, possibly due to an incomplete fix for CVE-2004-2103.2.
GHSA
GHSA-vhj4-jgw5-6cm4: Cross-site scripting (XSS) vulnerability in Novell NetWare Enterprise Web Server 5
ghsa_unreviewed·2022-04-29
CVE-2004-2103 [MEDIUM] GHSA-vhj4-jgw5-6cm4: Cross-site scripting (XSS) vulnerability in Novell NetWare Enterprise Web Server 5
Cross-site scripting (XSS) vulnerability in Novell NetWare Enterprise Web Server 5.1 and 6.0 allows remote attackers to process arbitrary script or HTML as other users via (1) a malformed request for a Perl program with script in the filename, (2) the User.id parameter to the webacc servlet, (3) the GWAP.version parameter to webacc, or (4) a URL request for a .bas file with script in the filename.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://marc.info/?l=bugtraq&m=107487862304440&w=2http://support.novell.com/cgi-bin/search/searchtid.cgi?/10091529.htmhttp://www.osvdb.org/4949https://exchange.xforce.ibmcloud.com/vulnerabilities/14919http://marc.info/?l=bugtraq&m=107487862304440&w=2http://support.novell.com/cgi-bin/search/searchtid.cgi?/10091529.htmhttp://www.osvdb.org/4949https://exchange.xforce.ibmcloud.com/vulnerabilities/14919
2004-12-31
Published