Description
|
|
Two vulnerabilities have been identified in various Symantec products, which could be exploited to conduct cross site scripting and script injection attacks. These issues are caused by input validation errors in the Log Viewer (ccLgView.exe) feature when displaying event log data, which could allow attackers to cause arbitrary scripting code embedded in an email message to be executed by the user's browser when accessing the "View Logs - Email Filtering" option from the Statistics option of the Symantec Log Viewer.
|