This script is Copyright (C) 2009-2012 Tenable Network Security, Inc.
The remote web server contains a script that is prone to a cross-site
The version of Novell GroupWise WebAccess installed on the remote host
fails to sanitize user-supplied input via a POST request to the
'User.id' parameter of the '/gw/webacc' script before using it to
generate dynamic HTML output. An attacker may be able to leverage
this issue to inject arbitrary HTML and script code into a user's
browser to be executed within the security context of the affected
Note that this install is also likely affected by other cross-site
scripting and cross-site request forgery issues in its WebAccess
component as well as a buffer overflow in its GWIA component, although
Nessus has not checked for them.
See also :
Apply GroupWise 7.03 Hot Patch 2 (HP2) or GroupWise 8.0 Hot Patch 1
(HP1) or later.
Risk factor :
Medium / CVSS Base Score : 4.3
CVSS Temporal Score : 3.6
Public Exploit Available : true
Family: CGI abuses : XSS
Nessus Plugin ID: 35726 (groupwise_webaccess_userid_xss.nasl)
Bugtraq ID: 33541
CVE ID: CVE-2009-0273
The cookie settings on this website are set to 'allow all cookies' to give you the very best website experience. If you continue without changing these settings, you consent to this - but if you want, you can opt out of all cookies by clicking below.