Vulnerabilities > HP > Insight Diagnostics

DATE CVE VULNERABILITY TITLE RISK
2013-06-14 CVE-2013-3575 Improper Input Validation vulnerability in HP Insight Diagnostics 9.4.0.4710
hpdiags/frontend2/help/pageview.php in HP Insight Diagnostics 9.4.0.4710 does not properly restrict PHP include or require statements, which allows remote attackers to include arbitrary hpdiags/frontend2/help/ .html files via the path parameter.
network
low complexity
hp CWE-20
5.0
2013-06-14 CVE-2013-3574 Improper Input Validation vulnerability in HP Insight Diagnostics 9.4.0.4710
Absolute path traversal vulnerability in hpdiags/frontend2/commands/saveCompareConfig.php in HP Insight Diagnostics 9.4.0.4710 allows remote attackers to write data to arbitrary files via a full pathname in the argument to the devicePath (aka mount) parameter.
network
low complexity
hp CWE-20
7.8
2013-06-14 CVE-2013-3573 Improper Input Validation vulnerability in HP Insight Diagnostics 9.4.0.4710
HP Insight Diagnostics 9.4.0.4710 allows remote attackers to conduct unspecified injection attacks via unknown vectors.
network
low complexity
hp CWE-20
critical
10.0
2010-12-22 CVE-2010-4111 Cross-Site Scripting vulnerability in HP Insight Diagnostics
Cross-site scripting (XSS) vulnerability in HP Insight Diagnostics Online Edition before 8.5.1.3712 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
4.3
2010-09-10 CVE-2010-3003 Cross-Site Scripting vulnerability in HP Insight Diagnostics
Cross-site scripting (XSS) vulnerability in HP Insight Diagnostics Online Edition before 8.5.0-11 on Linux allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
network
hp CWE-79
4.3
2008-10-02 CVE-2008-3542 Permissions, Privileges, and Access Controls vulnerability in HP Insight Diagnostics
Unspecified vulnerability in HP Insight Diagnostics before 7.9.1.2402 allows remote attackers to read arbitrary files via unknown vectors.
network
low complexity
hp CWE-264
7.8