1 results (0.007 seconds)

CVSS: 4.3EPSS: 0%CPEs: 3EXPL: 0

Cross-site scripting (XSS) vulnerability on the HP 3Com OfficeConnect Gigabit VPN Firewall 3CREVF100-73 with firmware before 1.0.13 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: a separate XSS issue for HP System Management Homepage (SMH) was originally assigned CVE-2010-3010 due to a CNA error, but CVE-2010-3012 is the appropriate identifier for the SMH issue. La vulnerabilidad de tipo cross-site scripting (XSS) en el Firewall 3Com OfficeConnect Gigabit VPN 3CREVF100-73 de HP con versión de firmware anterior a 1.0.13, permite a los atacantes remotos inyectar script web o HTML arbitrario por medio de vectores no especificados. NOTA: un problema de XSS independiente para System Management Homepage (SMH) de HP se asignó originalmente al CVE-2010-3010 debido a un error de CNA, pero el CVE-2010-3012 es el identificador adecuado para el problema SMH. • http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c02507909 http://securitytracker.com/id?1024449 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •