First published: Wed Dec 08 2010(Updated: )
Cross-site scripting (XSS) vulnerability in the Contacts Application in HP Palm webOS before 2.0 allows remote attackers to inject arbitrary web script or HTML via a crafted vCard file.
Credit: hp-security-alert@hp.com
Affected Software | Affected Version | How to fix |
---|---|---|
LG webOS | <=1.4.5 | |
LG webOS | =1.4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-4109 has a medium severity level due to its potential to allow remote code execution through XSS attacks.
To fix CVE-2010-4109, upgrade to HP Palm webOS version 2.0 or higher to mitigate the vulnerability.
CVE-2010-4109 affects HP Palm webOS versions prior to 2.0, specifically 1.4.1 and up to 1.4.5.
CVE-2010-4109 allows attackers to inject arbitrary web scripts or HTML through malicious vCard files.
CVE-2010-4109 is less of a concern in modern environments due to the obsolescence of the affected webOS versions, but systems running those versions remain vulnerable.