RSS   Vulnerabilities for
'Intellisync wireless email express'
   RSS

2007-05-11
 
CVE-2007-2592

CWE-Other
 

 
Multiple cross-site scripting (XSS) vulnerabilities in Nokia Intellisync Mobile Suite 6.4.31.2, 6.6.0.107, and 6.6.2.2, possibly involving Novell Groupwise Mobile Server and Nokia Intellisync Wireless Email Express, allow remote attackers to inject arbitrary web script or HTML via the (1) username parameter to de/pda/dev_logon.asp and (2) multiple unspecified vectors in (a) usrmgr/registerAccount.asp, (b) de/create_account.asp, and other files.

 
 
CVE-2007-2591

CWE-Other
 

 
usrmgr/userList.asp in Nokia Intellisync Mobile Suite 6.4.31.2, 6.6.0.107, and 6.6.2.2, possibly involving Novell Groupwise Mobile Server and Nokia Intellisync Wireless Email Express, allows remote attackers to modify user account details and cause a denial of service (account deactivation) via the userid parameter in an update action.

 
 
CVE-2007-2590

CWE-200
 

 
Nokia Intellisync Mobile Suite 6.4.31.2, 6.6.0.107, and 6.6.2.2, possibly involving Novell Groupwise Mobile Server and Nokia Intellisync Wireless Email Express, allows remote attackers to obtain user names and other sensitive information via a direct request to (1) usrmgr/userList.asp or (2) usrmgr/userStatusList.asp.

 

 >>> Vendor: Nokia 34 Products
Ip440 firewall vpn appliance
Firewall appliance
6210 handset
Sgsn dx200
GGSN
Electronic documentation
IPSO
6310i
Series
Affix
9500
3210
7610
N70
Symbian
QT
Groupwise mobile server
Intellisync mobile suite
Intellisync wireless email express
N95
Series 40
6131 nfc
Symbian s60 browser
Nokia pc suite
N810 internet tablet
N82
Qtdemobrowser
Qt creator
Multimedia player
E75 firmware
E75
Pc suite
@vantage commander
I-240w-q gpon ont firmware


Copyright 2019, cxsecurity.com

 

Back to Top