← Back

CVE-2013-1086

nvd nist
Published: Apr 19, 2013Modified: Apr 29, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:N/I:P/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

Cross-site scripting (XSS) vulnerability in WebAccess in Novell GroupWise before 8.0.3 HP3, and 2012 before SP2, allows remote attackers to inject arbitrary web script or HTML via vectors involving an onError attribute.

Affected (50)

Products: Novell: Groupwise
1 product
Groupwise
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Novell
Version 2012
Version 2012 sp1
Version 2012 sp1_hp1
Configuration B
47 vulnerable
Vulnerable SoftwareAffected Versions
Novell
Up to 8.03
Version 5.2
Version 5.57e
Version 5.5
Version 6.0.1 sp1
Version 6.0
Version 6.5.2
Version 6.5.3
Version 6.5.4
Version 6.5.6
Version 6.5.7
Version 6.5
Version 6.5 sp1
Version 6.5 sp2
Version 6.5 sp3
Version 6.5 sp4
Version 6.5 sp5
Version 6.5 sp6
Version 7.0.3 hp4
Version 7.0.3 hp5
Version 7.0.4
Version 7.0.4 ftf
Version 7.01
Version 7.01 ir1
Version 7.02
Version 7.02 hp1
Version 7.02 hp1a
Version 7.02 hp2
Version 7.02 hp2r1
Version 7.03
Version 7.03 hp2
Version 7.03 hp3
Version 7.03 hp3+ftf
Version 7.03 hp
Version 7.0
Version 8.00 hp1
Version 8.00 hp2
Version 8.00 hp3
Version 8.01
Version 8.01 hp
Version 8.02
Version 8.02 hp1
Version 8.02 hp2
Version 8.02 hp3
Version 8.03
Version 8.03 hp1
Version 8.0

References (6)

Source: cve@mitre.org
Permissions Required
Source: cve@mitre.org
Third Party AdvisoryVendor Advisory
Source: cve@mitre.org
Issue Tracking
Source: af854a3a-2127-422b-91ae-364da2661108
Permissions Required
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue Tracking

Timeline

No history available yet.