Vulnerabilities > CVE-2007-3062 - Unspecified vulnerability in HP System Management Homepage
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN hp
nessus
Summary
Cross-site scripting (XSS) vulnerability in HP System Management Homepage (SMH) before 2.1.2 running on Linux and Windows allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 5 |
Nessus
NASL family | CGI abuses : XSS |
NASL id | HPSMH_2_1_2.NASL |
description | The version of HP System Management Homepage installed on the remote host fails to sanitize user input to unspecified parameters and scripts before using it to generate dynamic HTML. A remote attacker may be able to exploit these issues to cause arbitrary HTML and script code to be executed by a user |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 25352 |
published | 2007-06-01 |
reporter | This script is Copyright (C) 2007-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/25352 |
title | HP System Management Homepage < 2.1.2 Unspecified XSS |
code |
|
References
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01056592
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01056592
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01056592
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01056592
- http://jvn.jp/jp/JVN%2319240523/index.html
- http://jvn.jp/jp/JVN%2319240523/index.html
- http://osvdb.org/36829
- http://osvdb.org/36829
- http://secunia.com/advisories/25493
- http://secunia.com/advisories/25493
- http://www.kb.cert.org/vuls/id/292457
- http://www.kb.cert.org/vuls/id/292457
- http://www.securityfocus.com/bid/24256
- http://www.securityfocus.com/bid/24256
- http://www.securitytracker.com/id?1018179
- http://www.securitytracker.com/id?1018179
- http://www.vupen.com/english/advisories/2007/2013
- http://www.vupen.com/english/advisories/2007/2013
- https://exchange.xforce.ibmcloud.com/vulnerabilities/34656
- https://exchange.xforce.ibmcloud.com/vulnerabilities/34656