Anfälligkeitssuche        Suche in 219043 CVE Beschreibungen
und 99761 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.800293
Kategorie:Web application abuses
Titel:HP System Management Homepage Cross-site scripting Vulnerability
Zusammenfassung:This host is running HP System Management Homepage (SMH) and is; prone to Cross site scripting vulnerability.
Beschreibung:Summary:
This host is running HP System Management Homepage (SMH) and is
prone to Cross site scripting vulnerability.

Vulnerability Insight:
The flaw is caused by an input validation error in the 'proxy/smhui/getuiinfo'
script when processing the 'servercert' parameter.

Vulnerability Impact:
Successful exploitation will allow remote attackers to execute arbitrary
script on the user's web browser by injecting web script and steal cookie
based authentication credentials.

Affected Software/OS:
HP System Management Homepage (SMH) versions prior to 6.0 on all platforms.

Solution:
Upgrade to HP SMH version 6.0.0.96(for windows), 6.0.0-95(for linux) or later.

CVSS Score:
4.3

CVSS Vector:
AV:N/AC:M/Au:N/C:N/I:P/A:N

Querverweis: BugTraq ID: 38081
Common Vulnerability Exposure (CVE) ID: CVE-2009-4185
http://www.securityfocus.com/bid/38081
Bugtraq: 20100127 PR09-15: XSS injection vulnerability within HP System Management Homepage (Insight Manager) (Google Search)
http://www.securityfocus.com/archive/1/509195/100/0/threaded
HPdes Security Advisory: HPSBMA02504
http://marc.info/?l=bugtraq&m=126529736830358&w=2
HPdes Security Advisory: SSRT090220
http://www.procheckup.com/vulnerability_manager/vulnerabilities/pr09-15
http://www.securitytracker.com/id?1023541
http://secunia.com/advisories/38341
http://www.vupen.com/english/advisories/2010/0294
CopyrightCopyright (C) 2010 Greenbone Networks GmbH

Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2024 E-Soft Inc. Alle Rechte vorbehalten.