Multiple cross-site scripting (XSS) vulnerabilities in Highwall Enterprise and Highwall Endpoint 4.0.2.11045 management interface allow remote attackers to inject arbitrary web script or HTML via (1) an Access Point with a crafted SSID, (2) the name of the sensor WIDS, (3) the name of the Highwall EndPoint workstation, or other unspecified vectors.
Link | Tags |
---|---|
http://www.osvdb.org/29916 | vdb entry |
http://www.securityfocus.com/archive/1/449118/100/200/threaded | mailing list |
http://www.securityfocus.com/bid/20605 | vdb entry |
http://www.securityfocus.com/archive/1/449739/100/100/threaded | mailing list |