HP webOS Contacts Application CVE-2011-2408 Remote Script Code Injection Vulnerability
BID:49111
Info
HP webOS Contacts Application CVE-2011-2408 Remote Script Code Injection Vulnerability
| Bugtraq ID: | 49111 |
| Class: | Input Validation Error |
| CVE: |
CVE-2011-2408 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 10 2011 12:00AM |
| Updated: | Aug 10 2011 12:00AM |
| Credit: | HP |
| Vulnerable: |
HP webOS 3.0.0 |
| Not Vulnerable: |
HP webOS 3.0.2 |
Discussion
HP webOS Contacts Application CVE-2011-2408 Remote Script Code Injection Vulnerability
HP webOS is prone to a remote script-injection vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this issue to execute arbitrary HTML or JavaScript code within the context of the affected application.
webOS 3.0.0 is vulnerable.
HP webOS is prone to a remote script-injection vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this issue to execute arbitrary HTML or JavaScript code within the context of the affected application.
webOS 3.0.0 is vulnerable.
Exploit / POC
HP webOS Contacts Application CVE-2011-2408 Remote Script Code Injection Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
HP webOS Contacts Application CVE-2011-2408 Remote Script Code Injection Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
HP webOS Contacts Application CVE-2011-2408 Remote Script Code Injection Vulnerability
References:
References: