Cross-site scripting (XSS) vulnerability in the login page in the management interface in the Aruba 800 Mobility Controller 2.5.4.18 and earlier, and 2.4.8.6-FIPS and earlier, allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the /screens URI, related to the url variable.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
http://arubanetworks.com/support/alerts/aid-070907b.asc | |
http://www.securityfocus.com/bid/26465 | vdb entry |
http://www.securityfocus.com/archive/1/483778/100/0/threaded | mailing list |
http://securityreason.com/securityalert/3380 | third party advisory |
http://www.kb.cert.org/vuls/id/680449 | third party advisory us government resource |
http://osvdb.org/45301 | vdb entry |