Cross-site scripting (XSS) vulnerability in the Contacts Application in HP Palm webOS before 2.0 allows remote attackers to inject arbitrary web script or HTML via a crafted vCard file.Referenceshttp://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c02639302http://www.vupen.com/english/advisories/2010/3131http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c02639302http://www.securitytracker.com/id?1024827