The xvesa code in Novell Netware 6.5 SP2 and SP3 allows remote attackers to redirect the xsession without authentication via a direct request to GUIMirror/Start.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Netware | Novell | 6.5-sp2 (including) | 6.5-sp2 (including) |
| Netware | Novell | 6.5-sp3 (including) | 6.5-sp3 (including) |