ID

VAR-200911-0346


TITLE

HP ProCurve Switch Management Interface Multiple HTML Injection Vulnerabilities

Trust: 0.3

sources: BID: 37001

DESCRIPTION

HP ProCurve Switch web management interface is prone to multiple HTML-injection vulnerabilities. Attacker-supplied HTML and script code would execute in the context of the affected site, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user; other attacks are also possible.

Trust: 0.3

sources: BID: 37001

AFFECTED PRODUCTS

vendor:hpmodel:procurve switch 5308xl j4819ascope: - version: -

Trust: 0.3

vendor:hpmodel:procurve switch j4813ascope:eqversion:2524

Trust: 0.3

vendor:hpmodel:procurve switchscope:eqversion:2524

Trust: 0.3

vendor:hpmodel:procurve switch 5308xl e.08.42scope: - version: -

Trust: 0.3

vendor:hpmodel:procurve switch 5308xlscope: - version: -

Trust: 0.3

vendor:hpmodel:procurve switch i.07.31scope:eqversion:2824

Trust: 0.3

vendor:hpmodel:procurve switchscope:eqversion:2824

Trust: 0.3

vendor:hpmodel:procurve switch f.05.50scope:eqversion:2524

Trust: 0.3

sources: BID: 37001

THREAT TYPE

network

Trust: 0.3

sources: BID: 37001

TYPE

Input Validation Error

Trust: 0.3

sources: BID: 37001

EXTERNAL IDS

db:BIDid:37001

Trust: 0.3

sources: BID: 37001

REFERENCES

url:http://www.procurve.com/

Trust: 0.3

sources: BID: 37001

CREDITS

Bugs NotHugs

Trust: 0.3

sources: BID: 37001

SOURCES

db:BIDid:37001

LAST UPDATE DATE

2022-05-17T01:38:40.563000+00:00


SOURCES UPDATE DATE

db:BIDid:37001date:2009-11-12T16:36:00

SOURCES RELEASE DATE

db:BIDid:37001date:2009-11-11T00:00:00