HP System Management Homepage < 2.1.2 Unspecified XSS

medium Nessus Plugin ID 25352


The remote web server is susceptible to cross-site scripting attacks.


The version of HP System Management Homepage installed on the remote host fails to sanitize user input to unspecified parameters and scripts before using it to generate dynamic HTML. A remote attacker may be able to exploit these issues to cause arbitrary HTML and script code to be executed by a user's browser in the context of the affected website.


Upgrade to HP System Management Homepage 2.1.2 or later.

See Also


Plugin Details

Severity: Medium

ID: 25352

File Name: hpsmh_2_1_2.nasl

Version: 1.25

Type: remote

Published: 6/1/2007

Updated: 4/7/2022

Configuration: Enable thorough checks

Supported Sensors: Nessus

Risk Information


Risk Factor: Low

Score: 3.0


Risk Factor: Medium

Base Score: 4.3

Temporal Score: 3.7

Vector: CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Information

CPE: cpe:/a:hp:system_management_homepage

Required KB Items: www/hp_smh

Exploit Ease: No exploit is required

Patch Publication Date: 5/30/2007

Vulnerability Publication Date: 6/1/2007

Reference Information

CVE: CVE-2007-3062

BID: 24256

CWE: 20, 442, 629, 711, 712, 722, 725, 74, 750, 751, 79, 800, 801, 809, 811, 864, 900, 928, 931, 990