HP webOS Calendar Application Remote Script Code Injection Vulnerability
BID:49112
Info
HP webOS Calendar Application Remote Script Code Injection Vulnerability
| Bugtraq ID: | 49112 |
| Class: | Input Validation Error |
| CVE: |
CVE-2011-2409 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 10 2011 12:00AM |
| Updated: | Aug 10 2011 12:00AM |
| Credit: | hankei6km |
| Vulnerable: |
HP webOS 3.0.0 |
| Not Vulnerable: |
HP webOS 3.0.2 |
Discussion
HP webOS Calendar Application Remote Script Code Injection Vulnerability
HP webOS is prone to a remote script-injection vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this issue to execute arbitrary HTML or JavaScript code within the context of the affected application.
webOS 3.0.0 is vulnerable.
HP webOS is prone to a remote script-injection vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this issue to execute arbitrary HTML or JavaScript code within the context of the affected application.
webOS 3.0.0 is vulnerable.
Exploit / POC
HP webOS Calendar Application Remote Script Code Injection Vulnerability
To exploit this issue, attackers must entice an unsuspecting user into opening a specially crafted web page.
To exploit this issue, attackers must entice an unsuspecting user into opening a specially crafted web page.
Solution / Fix
HP webOS Calendar Application Remote Script Code Injection Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
HP webOS Calendar Application Remote Script Code Injection Vulnerability
References:
References: