Search/CVE-2006-4220
CVE

CVE-2006-4220

Multiple cross-site scripting (XSS) vulnerabilities in webacc in Novell GroupWise WebAccess before 7 Support Pack 3 Public Beta allow remote attackers to inject arbitrary web script or HTML via the (1) User.html, (2) Error, (3) User.Theme.index, and (4) and User.lang parameters.

CVSS v3.1
EPSS
1.93%
probability of exploitation in 30 days
CISA KEV
Not listed
no confirmed exploitation reported
News coverage
0
sources referencing this CVE
Connections
3 relationships
Timeline
disclosure → media coverage
Dec 31, 2006
Disclosure — published as a CVE record. · last revised by NVD Apr 23, 2026