HP Select Access Unspecified Cross Site Scripting Vulnerability
BID:33505
Info
HP Select Access Unspecified Cross Site Scripting Vulnerability
| Bugtraq ID: | 33505 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 29 2009 12:00AM |
| Updated: | Jan 30 2009 04:09PM |
| Credit: | HP |
| Vulnerable: |
HP OpenView Select Access 6.2 HP OpenView Select Access 6.1 |
| Not Vulnerable: | |
Discussion
HP Select Access Unspecified Cross Site Scripting Vulnerability
HP Select Access is prone to a cross-site scripting vulnerability caused by an unspecified error.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may let the attacker steal cookie-based authentication credentials and launch other attacks.
The issue affects HP Select Access 6.1 and 6.2.
HP Select Access is prone to a cross-site scripting vulnerability caused by an unspecified error.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may let the attacker steal cookie-based authentication credentials and launch other attacks.
The issue affects HP Select Access 6.1 and 6.2.
Exploit / POC
HP Select Access Unspecified Cross Site Scripting Vulnerability
To exploit this issue, an attacker must entice an unsuspecting victim into following a malicious URI.
To exploit this issue, an attacker must entice an unsuspecting victim into following a malicious URI.
Solution / Fix
HP Select Access Unspecified Cross Site Scripting Vulnerability
Solution:
The vendor released fixes to address this issue. Please see the references for more information.
Solution:
The vendor released fixes to address this issue. Please see the references for more information.
References
HP Select Access Unspecified Cross Site Scripting Vulnerability
References:
References: