CVE-2012-2960
Published Aug 8, 2012
Last updated 12 years ago
Overview
- Description
- Cross-site scripting (XSS) vulnerability in the import functionality in HP ArcSight Connector appliance 6.2.0.6244.0 and ArcSight Logger appliance 5.2.0.6288.0 allows remote attackers to inject arbitrary web script or HTML via a crafted file.
- Source
- cret@cert.org
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 4.3
- Impact score
- 2.9
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:N/I:P/A:N
Weaknesses
- nvd@nist.gov
- CWE-79
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:hp:arcsight_connector_appliance_firmware:6.0.0.60023.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B2141CAA-CE07-4960-80A6-A40F3DF5A098" }, { "criteria": "cpe:2.3:o:hp:arcsight_connector_appliance_firmware:6.2.0.6244.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "86EC1A47-C2D0-4C09-8DE2-34BFE93F99FD" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:hp:arcsight_connector_appliance:c1400:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A21CDD36-0329-4BBC-B084-25608916AB0E" }, { "criteria": "cpe:2.3:h:hp:arcsight_connector_appliance:c3400:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "91D2E8EF-849E-42CC-8240-99726CA9CAD2" }, { "criteria": "cpe:2.3:h:hp:arcsight_connector_appliance:c5400:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9ACF7610-B34F-4D97-AD02-8BC5FAF29D42" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:hp:arcsight_logger_appliance_firmware:5.2.0.6288.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BFBB195D-4065-46C2-8E1E-5A0A024CAD52" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:hp:arcsight_logger_appliance:l7400-san:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0F1A055E-DCAB-4C92-B9E7-A057F544F030" } ], "operator": "OR" } ], "operator": "AND" } ]