Page 3 of 12 results (0.011 seconds)

CVSS: 4.3EPSS: 1%CPEs: 15EXPL: 0

Cross-site scripting (XSS) vulnerability in HP Version Control Repository Manager (VCRM) before 6.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en HP Version Control Repository Manager (VCRM) anterior a v6.2 permite a los atacantes remotos inyectar código web o HTML a través de vectores no especificados. • http://marc.info/?l=bugtraq&m=128811016023086&w=2 http://osvdb.org/68907 http://secunia.com/advisories/41998 http://securitytracker.com/id?1024644 http://www.securityfocus.com/bid/44431 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 2.1EPSS: 0%CPEs: 10EXPL: 0

HP Version Control Repository Manager (VCRM) before 2.1.1.730 does not properly handle the "@" character in a proxy password, which could allow attackers with physical access to obtain portions of the password when it is displayed to the screen. • http://secunia.com/advisories/15790 http://securitytracker.com/id?1014267 http://www.securityfocus.com/advisories/8734 http://www.securityfocus.com/bid/14032 •