First published: Tue Nov 02 2010(Updated: )
Cross-site scripting (XSS) vulnerability in Attachmate Reflection for the Web 2008 R2 (builds 10.1.569 and earlier), 2008 R1, and 9.6 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microfocus Reflection For The Web | <=9.6 | |
Microfocus Reflection For The Web | =9.0 | |
Microfocus Reflection For The Web | =2008-r1 | |
Microfocus Reflection For The Web | =9.01 | |
Microfocus Reflection For The Web | =9.5 | |
Microfocus Reflection For The Web | =8.0 | |
Microfocus Reflection For The Web | <=2008 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-4146 has a medium severity rating due to its potential for exploitation via cross-site scripting.
To fix CVE-2010-4146, update Attachmate Reflection for the Web to a version that is not affected, specifically later than 9.6.
CVE-2010-4146 affects several versions of Attachmate Reflection for the Web, including builds 10.1.569 and earlier, 2008 R1, and 9.6 and earlier.
Yes, successful exploitation of CVE-2010-4146 could allow attackers to steal sensitive information through injected scripts.
CVE-2010-4146 can facilitate cross-site scripting attacks, enabling attackers to manipulate web content to their advantage.