First published: Tue Jul 19 2011(Updated: )
Cross-site scripting (XSS) vulnerability in Windows Event Log SmartConnector in HP ArcSight Connector Appliance before 6.1 allows remote attackers to inject arbitrary web script or HTML via the Windows XP variable in a file.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
Hp Arcsight C5400 Appliance | ||
Hp Arcsight C5200 Appliance | ||
Hp Arcsight C3200 Appliance | ||
Hp Arcsight C3400 Appliance | ||
Hp Arcsight C1300 Appliance | ||
Hp Arcsight C1000 Appliance | ||
Hp Windows Event Log Smartconnector | <=6.0.0.60023.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2011-0770 is considered to be medium due to its potential for XSS attacks.
To fix CVE-2011-0770, update the HP ArcSight Connector Appliance to version 6.1 or later.
CVE-2011-0770 affects multiple HP ArcSight Connector Appliances, including the C1000, C1300, C3200, C3400, C5200, and C5400 models.
CVE-2011-0770 is a cross-site scripting (XSS) vulnerability that allows an attacker to inject arbitrary web scripts.
Yes, CVE-2011-0770 can be exploited remotely by attackers through the affected web interface.