Description
Cross-site scripting (XSS) vulnerability in esp/editUser.esp in the Palo Alto Networks firewall 3.0.x before 3.0.9 and 3.1.x before 3.1.1 allows remote attackers to inject arbitrary web script or HTML via the role parameter.
Affected products
References
- MISChttp://www.securityfocus.com/bid/40113
- MISChttp://www.jeromiejackson.com/index.php?view=article&id=83:palo-alto-cross-site-scripting-vulnerability&tmpl=component&print=1&layout=default&page=
- MISChttps://exchange.xforce.ibmcloud.com/vulnerabilities/58624
- MISChttp://archives.neohapsis.com/archives/bugtraq/2010-05/0086.html