HP System Management Homepage (SMH) for Linux, Windows, and HP-UX Cross Site Scripting Vulnerability
BID:25953
Info
HP System Management Homepage (SMH) for Linux, Windows, and HP-UX Cross Site Scripting Vulnerability
| Bugtraq ID: | 25953 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-5302 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 03 2007 12:00AM |
| Updated: | May 07 2015 05:35PM |
| Credit: | The vendor disclosed this issue. |
| Vulnerable: |
HP System Management Homepage 2.1.9 HP System Management Homepage 2.1.8 HP System Management Homepage 2.1.7 HP System Management Homepage 2.1.6 HP System Management Homepage 2.1.5 HP System Management Homepage 2.1.4 HP System Management Homepage 2.1.3 .132 HP System Management Homepage 2.1.3 HP System Management Homepage 2.1.2 HP System Management Homepage 2.1.1 HP System Management Homepage 2.1 HP System Management Homepage 2.0.2 HP System Management Homepage 2.0.1 HP System Management Homepage 2.0 HP HP-UX B.11.31 HP HP-UX B.11.23 HP HP-UX B.11.11 |
| Not Vulnerable: |
HP System Management Homepage 2.1.10 |
Discussion
HP System Management Homepage (SMH) for Linux, Windows, and HP-UX Cross Site Scripting Vulnerability
HP System Management Homepage is prone to a cross-site scripting vulnerability.
Exploiting this vulnerability may allow an attacker to perform cross-site scripting attacks on unsuspecting users in the context of the affected website. As a result, the attacker may be able to steal cookie-based authentication credentials and to launch other attacks.
These versions are affected:
HP System Management Homepage (SMH) prior to 2.1.10 for Linux and Windows
HP-UX B.11.11
HP-UX B.11.23
HP-UX B.11.31
HP System Management Homepage is prone to a cross-site scripting vulnerability.
Exploiting this vulnerability may allow an attacker to perform cross-site scripting attacks on unsuspecting users in the context of the affected website. As a result, the attacker may be able to steal cookie-based authentication credentials and to launch other attacks.
These versions are affected:
HP System Management Homepage (SMH) prior to 2.1.10 for Linux and Windows
HP-UX B.11.11
HP-UX B.11.23
HP-UX B.11.31
Exploit / POC
HP System Management Homepage (SMH) for Linux, Windows, and HP-UX Cross Site Scripting Vulnerability
To exploit this issue, an attacker must entice an unsuspecting victim into following a malicious URI.
To exploit this issue, an attacker must entice an unsuspecting victim into following a malicious URI.
Solution / Fix
HP System Management Homepage (SMH) for Linux, Windows, and HP-UX Cross Site Scripting Vulnerability
Solution:
The vendor released an advisory and fixes to address this issue. Please see the references for more information.
HP HP-UX B.11.31
HP HP-UX B.11.11
HP HP-UX B.11.23
HP System Management Homepage 2.0
HP System Management Homepage 2.0.1
HP System Management Homepage 2.0.2
HP System Management Homepage 2.1
HP System Management Homepage 2.1.1
HP System Management Homepage 2.1.2
HP System Management Homepage 2.1.3 .132
HP System Management Homepage 2.1.3
HP System Management Homepage 2.1.4
HP System Management Homepage 2.1.5
HP System Management Homepage 2.1.6
HP System Management Homepage 2.1.7
HP System Management Homepage 2.1.8
HP System Management Homepage 2.1.9
Solution:
The vendor released an advisory and fixes to address this issue. Please see the references for more information.
HP HP-UX B.11.31
HP HP-UX B.11.11
HP HP-UX B.11.23
HP System Management Homepage 2.0
-
HP SMH vA.2.2.6.2
http://h20392.www2.hp.com/portal/swdepot/index.do
HP System Management Homepage 2.0.1
-
HP SMH vA.2.2.6.2
http://h20392.www2.hp.com/portal/swdepot/index.do
HP System Management Homepage 2.0.2
-
HP SMH vA.2.2.6.2
http://h20392.www2.hp.com/portal/swdepot/index.do
HP System Management Homepage 2.1
-
HP SMH vA.2.2.6.2
http://h20392.www2.hp.com/portal/swdepot/index.do
HP System Management Homepage 2.1.1
-
HP SMH vA.2.2.6.2
http://h20392.www2.hp.com/portal/swdepot/index.do
HP System Management Homepage 2.1.2
-
HP SMH vA.2.2.6.2
http://h20392.www2.hp.com/portal/swdepot/index.do
HP System Management Homepage 2.1.3 .132
-
HP SMH vA.2.2.6.2
http://h20392.www2.hp.com/portal/swdepot/index.do
HP System Management Homepage 2.1.3
-
HP SMH vA.2.2.6.2
http://h20392.www2.hp.com/portal/swdepot/index.do
HP System Management Homepage 2.1.4
-
HP SMH vA.2.2.6.2
http://h20392.www2.hp.com/portal/swdepot/index.do
HP System Management Homepage 2.1.5
-
HP SMH vA.2.2.6.2
http://h20392.www2.hp.com/portal/swdepot/index.do
HP System Management Homepage 2.1.6
-
HP SMH vA.2.2.6.2
http://h20392.www2.hp.com/portal/swdepot/index.do
HP System Management Homepage 2.1.7
-
HP SMH vA.2.2.6.2
http://h20392.www2.hp.com/portal/swdepot/index.do
HP System Management Homepage 2.1.8
-
HP SMH vA.2.2.6.2
http://h20392.www2.hp.com/portal/swdepot/index.do
HP System Management Homepage 2.1.9
-
HP SMH vA.2.2.6.2
http://h20392.www2.hp.com/portal/swdepot/index.do
References
HP System Management Homepage (SMH) for Linux, Windows, and HP-UX Cross Site Scripting Vulnerability
References:
References:
- HP System Management Homepage (HP)
- [security bulletin] HPSBMA02274 SSRT071445 rev.2 - HP SystemManagement Homepa ([email protected])
- [security bulletin] HPSBMA02274 SSRT071445 rev.3 - HP System Management Homepage (HP)
- HPSBMA02274 SSRT071445 rev.1 - HP System Management Homepage (SMH) for HP-UX, Re (Hewlett Packard)
- HPSBMA02275 SSRT071445 rev.1 - HP System Management Homepage (SMH) for Linux and (Hewlett Packard)