Search/CVE-2006-3817
CVE

CVE-2006-3817

Cross-site scripting (XSS) vulnerability in Novell GroupWise WebAccess 6.5 and 7 before 20060727 allows remote attackers to inject arbitrary web script or HTML via an encoded SCRIPT element in an e-mail message with the UTF-7 character set, as demonstrated by the "+ADw-SCRIPT+AD4-" sequence.

CVSS v3.1
EPSS
2.01%
probability of exploitation in 30 days
CISA KEV
Not listed
no confirmed exploitation reported
News coverage
0
sources referencing this CVE
EPSS Trend
Aug 16, 2026Sep 9, 2026
0.04pp
1.97% → 2.01% over 2 tracked changes
Connections
1 relationships
Timeline
disclosure → media coverage
Aug 11, 2006
Disclosure — published as a CVE record. · last revised by NVD Apr 16, 2026