CVE-2010-4109

HP Palm webOS < 2.0 - Cross-Site Scripting via Crafted vCard File

Title source: llm
STIX 2.1

Description

Cross-site scripting (XSS) vulnerability in the Contacts Application in HP Palm webOS before 2.0 allows remote attackers to inject arbitrary web script or HTML via a crafted vCard file.

References (3)

Core 3
Core References
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2010/3131
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1024827

Scores

EPSS 0.0062
EPSS Percentile 70.2%

Details

CWE
CWE-79
Status published
Products (2)
hp/palm_webos 1.4.1
hp/palm_webos < 1.4.5
Published Dec 08, 2010
Tracked Since Feb 18, 2026