CVE-2009-4185
05.02.2010, 22:30
Cross-site scripting (XSS) vulnerability in proxy/smhui/getuiinfo in HP System Management Homepage (SMH) before 6.0 allows remote attackers to inject arbitrary web script or HTML via the servercert parameter.
| Vendor | Product | Version |
|---|---|---|
| hp | system_management_homepage | 𝑥 ≤ 3.0.2.77 |
| hp | system_management_homepage | 2.0.0 |
| hp | system_management_homepage | 2.0.1 |
| hp | system_management_homepage | 2.0.2 |
| hp | system_management_homepage | 2.1 |
| hp | system_management_homepage | 2.1.0-103 |
| hp | system_management_homepage | 2.1.0-103\(a\) |
| hp | system_management_homepage | 2.1.0-109 |
| hp | system_management_homepage | 2.1.0-118 |
| hp | system_management_homepage | 2.1.1 |
| hp | system_management_homepage | 2.1.2 |
| hp | system_management_homepage | 2.1.2-127 |
| hp | system_management_homepage | 2.1.3 |
| hp | system_management_homepage | 2.1.3.132 |
| hp | system_management_homepage | 2.1.4 |
| hp | system_management_homepage | 2.1.4-143 |
| hp | system_management_homepage | 2.1.5 |
| hp | system_management_homepage | 2.1.5-146 |
| hp | system_management_homepage | 2.1.6 |
| hp | system_management_homepage | 2.1.6-156 |
| hp | system_management_homepage | 2.1.7 |
| hp | system_management_homepage | 2.1.7-168 |
| hp | system_management_homepage | 2.1.8 |
| hp | system_management_homepage | 2.1.8-177 |
| hp | system_management_homepage | 2.1.9 |
| hp | system_management_homepage | 2.1.9-178 |
| hp | system_management_homepage | 2.1.10 |
| hp | system_management_homepage | 2.1.10-186 |
| hp | system_management_homepage | 2.1.11 |
| hp | system_management_homepage | 2.1.11-197 |
| hp | system_management_homepage | 2.1.12-118 |
| hp | system_management_homepage | 2.1.12-200 |
| hp | system_management_homepage | 2.1.15-210 |
| hp | system_management_homepage | 2.2.6 |
| hp | system_management_homepage | 2.2.8 |
| hp | system_management_homepage | 3.0.0-68 |
| hp | system_management_homepage | 3.0.1.73 |
𝑥
= Vulnerable software versions
References