AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2006-4220

MEDIUM · CVSS 4.3 EPSS 1.93%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2006-12-31 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2006-4220
Severity
MEDIUM
CVSS
4.3
EPSS
1.93%

Original NVD Description

Multiple cross-site scripting (XSS) vulnerabilities in webacc in Novell GroupWise WebAccess before 7 Support Pack 3 Public Beta allow remote attackers to inject arbitrary web script or HTML via the (1) User.html, (2) Error, (3) User.Theme.index, and (4) and User.lang parameters.