Description
Multiple cross-site scripting (XSS) vulnerabilities in the web interface in Aruba Mobility Controller 2.4.8.x-FIPS, 2.5.5.x, 2.5.6.x, 3.1.1.x, 3.2.0.x, and 3.3.1.x allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected products
- aruba_networks / aruba_mobility_controller2.4.8 – 2.4.8
- aruba_networks / aruba_mobility_controller2.4.8 – 2.4.8
- aruba_networks / aruba_mobility_controller2.5.5 – 2.5.5
- aruba_networks / aruba_mobility_controller2.5.6 – 2.5.6
- aruba_networks / aruba_mobility_controller3.1.1 – 3.1.1
- aruba_networks / aruba_mobility_controller3.2.0 – 3.2.0
- aruba_networks / aruba_mobility_controller3.3.1 – 3.3.1
References
- MISChttp://www.arubanetworks.com/support/alerts/aid-051408.asc
- MISChttp://www.securitytracker.com/id?1020033
- MISChttp://www.securityfocus.com/archive/1/492113/100/0/threaded
- MISChttps://exchange.xforce.ibmcloud.com/vulnerabilities/42433
- MISChttp://www.securityfocus.com/bid/29240
- VENDOR_ADVISORYhttp://secunia.com/advisories/30262