Búsqueda de    
Vulnerabilidad   
    Buscar 219043 Descripciones CVE y
99761 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.900658
Categoría:Web application abuses
Título:HP System Management Homepage Unspecified XSS Vulnerability
Resumen:This host is running HP System Management Homepage (SMH) and is; prone to cross-site scripting vulnerability.
Descripción:Summary:
This host is running HP System Management Homepage (SMH) and is
prone to cross-site scripting vulnerability.

Vulnerability Insight:
HP System Management Homepage application fails to validate user supplied
input.

Vulnerability Impact:
Successful exploitation will allow attackers to steal cookie-based
authentication credentials and execute arbitrary script on the user's
web browser by injecting web script or HTML vi remote vectors.

Affected Software/OS:
HP System Management Homepage versions prior to 3.0.1.73 on all platforms.

Solution:
Upgrade to version 3.0.1.73 or later.

CVSS Score:
4.3

CVSS Vector:
AV:N/AC:M/Au:N/C:N/I:P/A:N

Referencia Cruzada: BugTraq ID: 35031
Common Vulnerability Exposure (CVE) ID: CVE-2009-1418
http://www.securityfocus.com/bid/35031
HPdes Security Advisory: HPSBMA02428
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01745065
HPdes Security Advisory: SSRT090048
http://jvn.jp/en/jp/JVN02331156/index.html
http://jvndb.jvn.jp/en/contents/2009/JVNDB-2009-000029.html
http://securitytracker.com/id?1022242
http://secunia.com/advisories/35108
XForce ISS Database: smh-win-unspecified-xss(50633)
https://exchange.xforce.ibmcloud.com/vulnerabilities/50633
CopyrightCopyright (C) 2009 Greenbone Networks GmbH

Esta es sólo una de 99761 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2024 E-Soft Inc. Todos los derechos reservados.