CVE-2009-4185

Cross-site scripting (XSS) vulnerability in proxy/smhui/getuiinfo in HP System Management Homepage (SMH) before 6.0 allows remote attackers to inject arbitrary web script or HTML via the servercert parameter.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
hpCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 71%
VendorProductVersion
hpsystem_management_homepage
𝑥
≤ 3.0.2.77
hpsystem_management_homepage
2.0.0
hpsystem_management_homepage
2.0.1
hpsystem_management_homepage
2.0.2
hpsystem_management_homepage
2.1
hpsystem_management_homepage
2.1.0-103
hpsystem_management_homepage
2.1.0-103\(a\)
hpsystem_management_homepage
2.1.0-109
hpsystem_management_homepage
2.1.0-118
hpsystem_management_homepage
2.1.1
hpsystem_management_homepage
2.1.2
hpsystem_management_homepage
2.1.2-127
hpsystem_management_homepage
2.1.3
hpsystem_management_homepage
2.1.3.132
hpsystem_management_homepage
2.1.4
hpsystem_management_homepage
2.1.4-143
hpsystem_management_homepage
2.1.5
hpsystem_management_homepage
2.1.5-146
hpsystem_management_homepage
2.1.6
hpsystem_management_homepage
2.1.6-156
hpsystem_management_homepage
2.1.7
hpsystem_management_homepage
2.1.7-168
hpsystem_management_homepage
2.1.8
hpsystem_management_homepage
2.1.8-177
hpsystem_management_homepage
2.1.9
hpsystem_management_homepage
2.1.9-178
hpsystem_management_homepage
2.1.10
hpsystem_management_homepage
2.1.10-186
hpsystem_management_homepage
2.1.11
hpsystem_management_homepage
2.1.11-197
hpsystem_management_homepage
2.1.12-118
hpsystem_management_homepage
2.1.12-200
hpsystem_management_homepage
2.1.15-210
hpsystem_management_homepage
2.2.6
hpsystem_management_homepage
2.2.8
hpsystem_management_homepage
3.0.0-68
hpsystem_management_homepage
3.0.1.73
𝑥
= Vulnerable software versions