HP System Management Homepage Unspecified HTTP Response Splitting Vulnerability
BID:43269
Info
HP System Management Homepage Unspecified HTTP Response Splitting Vulnerability
| Bugtraq ID: | 43269 |
| Class: | Input Validation Error |
| CVE: |
CVE-2010-3011 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 15 2010 12:00AM |
| Updated: | Sep 15 2010 12:00AM |
| Credit: | The vendor |
| Vulnerable: |
HP System Management Homepage 6.1 HP System Management Homepage 6.0 |
| Not Vulnerable: |
HP System Management Homepage 6.2 |
Discussion
HP System Management Homepage Unspecified HTTP Response Splitting Vulnerability
HP System Management Homepage is prone to an HTTP response-splitting vulnerability.
Attackers can leverage this issue to influence or misrepresent how web content is served, cached, or interpreted. This could aid in various attacks that try to entice client users into a false sense of trust.
HP System Management Homepage versions prior to 6.2 are vulnerable.
HP System Management Homepage is prone to an HTTP response-splitting vulnerability.
Attackers can leverage this issue to influence or misrepresent how web content is served, cached, or interpreted. This could aid in various attacks that try to entice client users into a false sense of trust.
HP System Management Homepage versions prior to 6.2 are vulnerable.
Exploit / POC
HP System Management Homepage Unspecified HTTP Response Splitting Vulnerability
To exploit this issue, an attacker must entice an unsuspecting victim to follow a malicious URI.
To exploit this issue, an attacker must entice an unsuspecting victim to follow a malicious URI.
Solution / Fix
HP System Management Homepage Unspecified HTTP Response Splitting Vulnerability
Solution:
Updates are available; please see the references for more information.
Solution:
Updates are available; please see the references for more information.