CVE-2011-2224

EUVD-2011-2213
The Mobility Pack before 1.2 in Novell Data Synchronizer 1.x through 1.1.2 build 428 does not include the HTTPOnly flag in a Set-Cookie header, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via unspecified vectors.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 67%
Affected Products (NVD)
VendorProductVersion
novelldata_synchronizer
1.0.0
novelldata_synchronizer
1.1.0
novelldata_synchronizer
1.1.1
novelldata_synchronizer
1.1.2
novellmobility_pack
𝑥
≤ 1.1.2
novellmobility_pack
1.0
novellmobility_pack
1.1
novellmobility_pack
1.1.1
𝑥
= Vulnerable software versions