First published: Thu Oct 28 2010(Updated: )
Cross-site scripting (XSS) vulnerability in HP Version Control Repository Manager (VCRM) before 6.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Credit: hp-security-alert@hp.com
Affected Software | Affected Version | How to fix |
---|---|---|
HP Version Control Repository Manager | =2.1.1.710 | |
HP Version Control Repository Manager | =1.0.1288.1 | |
HP Version Control Repository Manager | =2.0.0.50 | |
HP Version Control Repository Manager | =1.0.2241.0 | |
HP Version Control Repository Manager | =6.0.2 | |
HP Version Control Repository Manager | =1.0.3085.0 | |
HP Version Control Repository Manager | =1.0.2289.0 | |
HP Version Control Repository Manager | =6.1 | |
HP Version Control Repository Manager | =6.0.1 | |
HP Version Control Repository Manager | =1.0.2345.0 | |
HP Version Control Repository Manager | =2.1.1.720 | |
HP Version Control Repository Manager | <=6.1.2 | |
HP HP | =version_control_repository_manager-6.0 | |
HP Version Control Repository Manager | =1.0.3086.0 | |
HP Version Control Repository Manager | =2.0.1.30 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2010-3994 is not explicitly categorized but it is recognized as a cross-site scripting (XSS) vulnerability which can potentially allow remote attackers to inject arbitrary scripts.
To fix CVE-2010-3994, upgrade to HP Version Control Repository Manager version 6.2 or later.
CVE-2010-3994 affects several versions of HP Version Control Repository Manager including 1.0.1288.1, 2.1.1.710, and others up to 6.1.2.
Yes, CVE-2010-3994 can be exploited remotely since it allows attackers to inject arbitrary web scripts or HTML through unspecified vectors.
CVE-2010-3994 is classified as a cross-site scripting (XSS) vulnerability.