Cross-site scripting (XSS) vulnerability in the Contacts Application in HP Palm webOS before 2.0 allows remote attackers to inject arbitrary web script or HTML via a crafted vCard file.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c02639302 | vendor advisory |
http://www.vupen.com/english/advisories/2010/3131 | vdb entry vendor advisory |
http://www.securitytracker.com/id?1024827 | vdb entry |