Описание
Cross-site scripting (XSS) vulnerability in Symantec SecurityExpressions Audit and Compliance Server 4.1.1, 4.1, and earlier allows remote attackers to inject arbitrary web script or HTML via vectors that trigger an error message in a response, related to an "HTML Injection issue."
Cross-site scripting (XSS) vulnerability in Symantec SecurityExpressions Audit and Compliance Server 4.1.1, 4.1, and earlier allows remote attackers to inject arbitrary web script or HTML via vectors that trigger an error message in a response, related to an "HTML Injection issue."
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2009-3030
- https://exchange.xforce.ibmcloud.com/vulnerabilities/53669
- http://secunia.com/advisories/36972
- http://securitytracker.com/id?1022989
- http://www.osvdb.org/58650
- http://www.securityfocus.com/bid/36571
- http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2009&suid=20091006_00
- http://www.vupen.com/english/advisories/2009/2849
Связанные уязвимости
Cross-site scripting (XSS) vulnerability in Symantec SecurityExpressions Audit and Compliance Server 4.1.1, 4.1, and earlier allows remote attackers to inject arbitrary web script or HTML via vectors that trigger an error message in a response, related to an "HTML Injection issue."