HP Network Automation Multiple Vulnerabilities (HPSBMU02693)

medium Nessus Plugin ID 70100

Synopsis

The remote application has multiple vulnerabilities.

Description

The HP Network Automation server is susceptible to XSS and SQL injection attacks.

Solution

Upgrade to version 9.10.01 or later.

See Also

http://www.nessus.org/u?f89a79de

Plugin Details

Severity: Medium

ID: 70100

File Name: hp_na_hpsbmu02693.nasl

Version: 1.9

Type: remote

Family: CGI abuses

Published: 9/24/2013

Updated: 1/19/2021

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.6

CVSS v2

Risk Factor: Medium

Base Score: 6.5

Temporal Score: 5.4

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Information

CPE: cpe:/a:hp:network_automation

Required KB Items: www/hp_network_automation

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 7/28/2011

Vulnerability Publication Date: 7/28/2011

Reference Information

CVE: CVE-2011-2402, CVE-2011-2403

BID: 48922, 48924

CWE: 20, 442, 629, 711, 712, 722, 725, 74, 750, 751, 79, 800, 801, 809, 811, 864, 900, 928, 931, 990