Collected research
CSRF on Novell GroupWise WebAccess
CSRF on Novell GroupWise WebAccess allows email theft and other attacks
Novell GroupWise WebAccess 6.5x through 8.0 tokenises nothing, so any authenticated request can be forged from a page, a link, or the HTML body of a mail the victim merely opens. The advisory's point is persistence: forging the add-forwarding-rule request installs a silent backdoor that copies every future message to the attacker. CVE-2009-0272; PoC withheld at Novell's request.
Record
- Document
- CSRF on Novell GroupWise WebAccess allows email theft and other attacks
- Researcher
- Adrian Pastor
- Published by
- procheckup.com
- Topic
- Other
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Adrian Pastor, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .