CVE-2012-2960: XSS
Cross-site scripting (XSS) vulnerability in the import functionality in HP ArcSight Connector appliance 6.2.0.6244.0 and ArcSight Logger appliance 5.2.0.6288.0 allows remote attackers to inject arbitrary web script or HTML via a crafted file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-2960?
CVE-2012-2960 is classified as a medium severity cross-site scripting vulnerability.
How do I fix CVE-2012-2960?
To fix CVE-2012-2960, users should apply the latest firmware updates for the affected HP ArcSight products.
What products are affected by CVE-2012-2960?
CVE-2012-2960 affects HP ArcSight Connector appliance versions 6.2.0.6244.0 and 6.0.0.60023.2, as well as ArcSight Logger appliance version 5.2.0.6288.0.
What type of vulnerability is CVE-2012-2960?
CVE-2012-2960 is a cross-site scripting (XSS) vulnerability that allows attackers to inject arbitrary web scripts.
Can CVE-2012-2960 be exploited remotely?
Yes, CVE-2012-2960 can be exploited remotely by attackers through crafted files.