CVE-2012-2960

HP ArcSight Connector Appliance 6.2.0.6244.0 and Logger Appliance 5.2.0.6288.0 XSS via Import

Title source: llm
STIX 2.1

Description

Cross-site scripting (XSS) vulnerability in the import functionality in HP ArcSight Connector appliance 6.2.0.6244.0 and ArcSight Logger appliance 5.2.0.6288.0 allows remote attackers to inject arbitrary web script or HTML via a crafted file.

References (2)

Core 2
Core References
US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/960468

Scores

EPSS 0.0074
EPSS Percentile 73.2%

Details

CWE
CWE-79
Status published
Products (7)
hp/arcsight_connector_appliance c1400
hp/arcsight_connector_appliance c3400
hp/arcsight_connector_appliance c5400
hp/arcsight_connector_appliance_firmware 6.0.0.60023.2
hp/arcsight_connector_appliance_firmware 6.2.0.6244.0
hp/arcsight_logger_appliance l7400-san
hp/arcsight_logger_appliance_firmware 5.2.0.6288.0
Published Aug 08, 2012
Tracked Since Feb 18, 2026