HP WebOS Email Application Multiple HTML Injection Vulnerabilities
BID:47787
Info
HP WebOS Email Application Multiple HTML Injection Vulnerabilities
| Bugtraq ID: | 47787 |
| Class: | Input Validation Error |
| CVE: |
CVE-2011-1737 |
| Remote: | Yes |
| Local: | No |
| Published: | May 10 2011 12:00AM |
| Updated: | May 10 2011 12:00AM |
| Credit: | HP |
| Vulnerable: |
HP webOS 1.4.5 HP webOS 1.4.5.1 |
| Not Vulnerable: | |
Discussion
HP WebOS Email Application Multiple HTML Injection Vulnerabilities
HP WebOS is prone to multiple HTML-injection vulnerabilities that affect the email application.
Attacker-supplied HTML or JavaScript code could run in the context of the affected site, potentially allowing the attacker to steal cookie-based authentication credentials and to control how the site is rendered to the user.
HP WebOS is prone to multiple HTML-injection vulnerabilities that affect the email application.
Attacker-supplied HTML or JavaScript code could run in the context of the affected site, potentially allowing the attacker to steal cookie-based authentication credentials and to control how the site is rendered to the user.
Exploit / POC
HP WebOS Email Application Multiple HTML Injection Vulnerabilities
An attacker can exploit this issue by using readily available email applications.
An attacker can exploit this issue by using readily available email applications.
Solution / Fix
HP WebOS Email Application Multiple HTML Injection Vulnerabilities
Solution:
The vendor released an update. Please see the references for details.
Solution:
The vendor released an update. Please see the references for details.
References
HP WebOS Email Application Multiple HTML Injection Vulnerabilities
References:
References:
- Palm WebOS Homepage (Palm)