HP System Management Homepage < 2.1.2 Unspecified XSS

medium Nessus Plugin ID 25352

Synopsis

The remote web server is susceptible to cross-site scripting attacks.

Description

The version of HP System Management Homepage installed on the remote host fails to sanitize user input to unspecified parameters and scripts before using it to generate dynamic HTML. A remote attacker may be able to exploit these issues to cause arbitrary HTML and script code to be executed by a user's browser in the context of the affected website.

Solution

Upgrade to HP System Management Homepage 2.1.2 or later.

See Also

http://www.securityfocus.com/advisories/12545

Plugin Details

Severity: Medium

ID: 25352

File Name: hpsmh_2_1_2.nasl

Version: 1.25

Type: remote

Published: 6/1/2007

Updated: 4/7/2022

Configuration: Enable thorough checks

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Low

Score: 3.0

CVSS v2

Risk Factor: Medium

Base Score: 4.3

Temporal Score: 3.7

Vector: CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Information

CPE: cpe:/a:hp:system_management_homepage

Required KB Items: www/hp_smh

Exploit Ease: No exploit is required

Patch Publication Date: 5/30/2007

Vulnerability Publication Date: 6/1/2007

Reference Information

CVE: CVE-2007-3062

BID: 24256

CWE: 20, 442, 629, 711, 712, 722, 725, 74, 750, 751, 79, 800, 801, 809, 811, 864, 900, 928, 931, 990