First published: Wed Nov 02 2011(Updated: )
Cross-site scripting (XSS) vulnerability in the Web Administrator component in GE Intelligent Platforms Proficy Historian 4.x and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
GE Proficy Historian | <=4.0 | |
GE Proficy Historian | =3.1 | |
GE Proficy Historian | =3.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-3320 is classified as a moderate severity cross-site scripting vulnerability.
To fix CVE-2011-3320, update the GE Intelligent Platforms Proficy Historian software to version 4.0 or later.
CVE-2011-3320 affects versions 3.1, 3.5, and all versions up to and including 4.0 of GE Intelligent Platforms Proficy Historian.
CVE-2011-3320 allows remote attackers to inject arbitrary web scripts or HTML into web pages served by the affected product.
Yes, CVE-2011-3320 can be exploited remotely by attackers targeting the web interface of the affected software.