This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Detail
Vendor Hp First view 2009-10-13
Product Color Laserjet cm4730 Mfp Last view 2009-10-13
Version Type Hardware
Update  
Edition  
Language  
Sofware Edition  
Target Software  
Target Hardware  
Other  

Activity : Overall

COMMON PLATFORM ENUMERATION: Repartition per Version

CPE Name Affected CVE
cpe:2.3:h:hp:color_laserjet_cm4730_mfp:*:*:*:*:*:*:*:* 1

Related : CVE

  Date Alert Description
4.3 2009-10-13 CVE-2009-2684

Multiple cross-site scripting (XSS) vulnerabilities in Jetdirect and the Embedded Web Server (EWS) on certain HP LaserJet and Color LaserJet printers, and HP Digital Senders, allow remote attackers to inject arbitrary web script or HTML via the (1) Product_URL or (2) Tech_URL parameter in an Apply action to the support_param.html/config script.

CWE : Common Weakness Enumeration

%idName
100% (1) CWE-79 Failure to Preserve Web Page Structure ('Cross-site Scripting')

Open Source Vulnerability Database (OSVDB)

id Description
58715 HP Multiple Products support_param.html/config Multiple Parameter XSS

ExploitDB Exploits

id Description
10055 HP Multiple LaserJet Printer xss
10011 HP LaserJet printers - Multiple Stored XSS vulnerabilities