CVE-2009-5097
N/A
N/A
Summary
Palm Pre WebOS 1.1 and earlier processes JavaScript in email messages, which allows remote attackers to execute arbitrary JavaScript, as demonstrated by reading PalmDatabase.db3.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | n/a | n/a | affected |
Weaknesses
- n/a
ADP Enrichment
CVE Program Container
Additional References
- http://kb.palm.com/wps/portal/kb/na/pre/p100eww/sprint/solutions/article/50607_en.html#12
- http://www.securitytracker.com/id?1022987
- http://tlhsecurity.blogspot.com/2009/10/palm-pre-webos-11-remote-file-access.html
- http://www.precentral.net/webos-1-2-fixed-serious-file-security-issue
- http://secunia.com/advisories/36936
References
- http://kb.palm.com/wps/portal/kb/na/pre/p100eww/sprint/solutions/article/50607_en.html#12
- http://www.securitytracker.com/id?1022987
- http://tlhsecurity.blogspot.com/2009/10/palm-pre-webos-11-remote-file-access.html
- http://www.precentral.net/webos-1-2-fixed-serious-file-security-issue
- http://secunia.com/advisories/36936
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.