First published: Thu Oct 15 2009(Updated: )
Cross-site scripting (XSS) vulnerability in Symantec SecurityExpressions Audit and Compliance Server 4.1.1, 4.1, and earlier allows remote attackers to inject arbitrary web script or HTML via vectors that trigger an error message in a response, related to an "HTML Injection issue."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Symantec SecurityExpressions Audit and Compliance Server | =4.1 | |
Symantec SecurityExpressions Audit and Compliance Server | <=4.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-3030 is considered a medium severity vulnerability due to its potential for cross-site scripting attacks.
To fix CVE-2009-3030, upgrade to Symantec SecurityExpressions Audit and Compliance Server version 4.1.2 or later.
CVE-2009-3030 can facilitate cross-site scripting attacks, allowing an attacker to inject malicious scripts into web pages.
CVE-2009-3030 affects Symantec SecurityExpressions Audit and Compliance Server versions 4.1 and 4.1.1, and earlier.
Exploiting CVE-2009-3030 can lead to unauthorized access, data theft, or session hijacking through injected scripts.