Cross-site scripting (XSS) vulnerability in HP Application Lifecycle Management (ALM) Quality Center before 11.51 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka ZDI-CAN-1565.
CVSS Vector
AV:N/AC:M/Au:N/C:N/I:P/A:NHP Application Lifecycle Management
APPHp11.00≤ 11.50
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
XSS
CWE
Related vulnerabilities
CVE-2013-4810CRITICAL9.8⚠ KEVPL ✓same product
RCE przez EJBInvokerServlet/JMXInvokerServlet w HP ProCurve Manager
CVE-2013-4834HIGH7.5same product
Unspecified vulnerability in the client component in HP Application LifeCycle Management (ALM) before 11 p11 a...
CVE-2013-4836HIGH7.5same product
Unspecified vulnerability in the GossipService SOAP Request implementation in the Synchronizer component befor...
CVE-2014-2631MEDIUM4.6same product
Unspecified vulnerability in HP Application Lifecycle Management (aka Quality Center) 11.5x and 12.0x allows l...
CVE-2017-5638CRITICAL9.8⚠ KEVPL ✓same vendor
RCE w Apache Struts 2 poprzez błędną obsługę nagłówków HTTP (Jakarta Multipart parser)