Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
146377 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.800293
Categoría:Web application abuses
Título:HP/HPE System Management Homepage (SMH) XSS Vulnerability (HPSBMA02504)
Resumen:HP/HPE System Management Homepage (SMH) is prone to a cross-site; scripting (XSS) vulnerability.
Descripción:Summary:
HP/HPE System Management Homepage (SMH) is prone to a cross-site
scripting (XSS) vulnerability.

Vulnerability Insight:
The flaw is caused by an input validation error in the
'proxy/smhui/getuiinfo' script when processing the 'servercert' parameter.

Vulnerability Impact:
Successful exploitation will allow remote attackers to execute
arbitrary script on the user's web browser by injecting web script and steal cookie based
authentication credentials.

Affected Software/OS:
HP/HPE SMH prior to version 6.0 on all platforms.

Solution:
Update to version 6.0.0.96 (for Windows), 6.0.0-95 (for Linux) or later.

CVSS Score:
4.3

CVSS Vector:
AV:N/AC:M/Au:N/C:N/I:P/A:N

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2009-4185
BugTraq ID: 38081
http://www.securityfocus.com/bid/38081
Bugtraq: 20100127 PR09-15: XSS injection vulnerability within HP System Management Homepage (Insight Manager) (Google Search)
http://www.securityfocus.com/archive/1/509195/100/0/threaded
HPdes Security Advisory: HPSBMA02504
http://marc.info/?l=bugtraq&m=126529736830358&w=2
HPdes Security Advisory: SSRT090220
http://www.procheckup.com/vulnerability_manager/vulnerabilities/pr09-15
http://www.securitytracker.com/id?1023541
http://secunia.com/advisories/38341
http://www.vupen.com/english/advisories/2010/0294
CopyrightCopyright (C) 2010 Greenbone Networks GmbH

Esta es sólo una de 146377 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.