HP System Management Homepage 'servercert' Parameter Cross Site Scripting Vulnerability
BID:37968
Info
HP System Management Homepage 'servercert' Parameter Cross Site Scripting Vulnerability
| Bugtraq ID: | 37968 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 27 2010 12:00AM |
| Updated: | Jan 27 2010 12:00AM |
| Credit: | Richard Brain of ProCheckUp Ltd |
| Vulnerable: |
HP System Management Homepage 3.0.2 .77 HP System Management Homepage 3.0 .68 HP System Management Homepage 3.0 .64 HP System Management Homepage 2.1.15 210 |
| Not Vulnerable: |
HP Systems Insight Manager 6.0.0.96 |
Discussion
HP System Management Homepage 'servercert' Parameter Cross Site Scripting Vulnerability
HP System Management Homepage, also known as Systems Insight Manager, is prone to a cross-site scripting vulnerability.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site and to steal cookie-based authentication credentials.
HP System Management Homepage, also known as Systems Insight Manager, is prone to a cross-site scripting vulnerability.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site and to steal cookie-based authentication credentials.
Exploit / POC
HP System Management Homepage 'servercert' Parameter Cross Site Scripting Vulnerability
An attacker can exploit this issue by enticing an unsuspecting victim to follow a malicious URI.
The following example URI is available:
An attacker can exploit this issue by enticing an unsuspecting victim to follow a malicious URI.
The following example URI is available:
Solution / Fix
HP System Management Homepage 'servercert' Parameter Cross Site Scripting Vulnerability
Solution:
Reports indicate that the vendor has addressed this issue, but this has not been confirmed. Please contact the vendor for more information.
Solution:
Reports indicate that the vendor has addressed this issue, but this has not been confirmed. Please contact the vendor for more information.
References
HP System Management Homepage 'servercert' Parameter Cross Site Scripting Vulnerability
References:
References:
- PR09-15: XSS injection vulnerability within HP System Management Homepage (Insig (research (researchprocheckup.com))
- PR09-15: XSS injection vulnerability within HP System Management Homepage (Insig (research
) - HP System Management Homepage (HP)