Executive Summary

Summary
Title HP System Management Homepage cross-site scripting vulnerability
Informations
Name VU#292457 First vendor Publication 2007-06-05
Vendor VU-CERT Last vendor Modification 2007-06-05
Severity (Vendor) N/A Revision M

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:M/Au:N/C:N/I:P/A:N)
Cvss Base Score 4.3 Attack Range Network
Cvss Impact Score 2.9 Attack Complexity Medium
Cvss Expoit Score 8.6 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

Vulnerability Note VU#292457

HP System Management Homepage cross-site scripting vulnerability

Overview

The HP System Management Homepage contains a cross-site scripting vulnerability.

I. Description

The HP System Management Homepage (SMH) server is a web-based interface that can manage HP servers running the Microsoft Windows or Linux operating systems.

The SMH contains an unspecified cross-site scripting vulnerability.

II. Impact

An attacker may be able to obtain sensitive data, corrupt or steal cookies, or take any action that the SMH server can.

III. Solution

Upgrade

HP has released SMH version 2.1.8-17 to address this issue.

Restrict access

Restricting network access to the SMH server using a firewall or access control lists may mitigate this vulnerability.

Systems Affected

VendorStatusDate Updated
Hewlett-Packard CompanyVulnerable5-Jun-2007

References


http://h18013.www1.hp.com/products/servers/management/agents/index.html
http://h20000.www2.hp.com/bc/docs/support/SupportManual/c00293371/c00293371.pdf
http://secunia.com/advisories/25493/

Credit

Thanks to HP for information that was used in this report.

This document was written by Ryan Giobbi.

Other Information

Date Public06/05/2007
Date First Published06/05/2007 02:37:14 PM
Date Last Updated06/05/2007
CERT Advisory 
CVE Name 
Metric0.13
Document Revision12

Original Source

Url : http://www.kb.cert.org/vuls/id/292457

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 5

Open Source Vulnerability Database (OSVDB)

Id Description
36829 HP System Management Homepage (SMH) Unspecified XSS

Nessus® Vulnerability Scanner

Date Description
2007-06-01 Name : The remote web server is susceptible to cross-site scripting attacks.
File : hpsmh_2_1_2.nasl - Type : ACT_GATHER_INFO