Multiple cross-site scripting (XSS) vulnerabilities in WebAccess in Novell GroupWise 8.0 before HP3 allow remote attackers to inject arbitrary web script or HTML via the (1) Directory.Item.name or (2) Directory.Item.displayName parameter.
| Software | From | Fixed in |
|---|---|---|
| novell / groupwise | 8.0-hp1 | 8.0-hp1.x |
| novell / groupwise | 8.0 | 8.0.x |
| novell / groupwise | 8.0-hp2 | 8.0-hp2.x |