ID

VAR-201101-0408


TITLE

Lexmark Printer Ready Message Value HTML Code Injection Vulnerability

Trust: 0.6

sources: CNVD: CNVD-2011-0081

DESCRIPTION

Lexmark Printer X651de is a printer from Lexmark, USA. The Lexmark Printer X651de has an HTML injection vulnerability in its implementation, which is not properly filtered when using user-provided input in dynamically generated content. A remote attacker could exploit this vulnerability to run HTML and script code in an affected printer web interface application, stealing cookie authentication credentials or controlling the appearance of the site. Other attacks are also possible. Lexmark Printer X651de is vulnerable; other versions may also be affected

Trust: 0.81

sources: CNVD: CNVD-2011-0081 // BID: 45688

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2011-0081

AFFECTED PRODUCTS

vendor:lexmarkmodel:laser printer x651descope: - version: -

Trust: 0.6

vendor:lexmarkmodel:x651descope: - version: -

Trust: 0.3

sources: CNVD: CNVD-2011-0081 // BID: 45688

THREAT TYPE

network

Trust: 0.3

sources: BID: 45688

TYPE

Input Validation Error

Trust: 0.3

sources: BID: 45688

EXTERNAL IDS

db:BIDid:45688

Trust: 0.9

db:CNVDid:CNVD-2011-0081

Trust: 0.6

sources: CNVD: CNVD-2011-0081 // BID: 45688

REFERENCES

url:http://www.securityfocus.com/bid/45688

Trust: 0.6

url:http://www1.lexmark.com/

Trust: 0.3

url:http://www1.lexmark.com/products/view/multifunction/lexmark-x651de/catid=cat10008-category&prodid=4662-product

Trust: 0.3

sources: CNVD: CNVD-2011-0081 // BID: 45688

CREDITS

dave b

Trust: 0.3

sources: BID: 45688

SOURCES

db:CNVDid:CNVD-2011-0081
db:BIDid:45688

LAST UPDATE DATE

2022-05-17T02:09:12.441000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2011-0081date:2011-01-11T00:00:00
db:BIDid:45688date:2011-01-06T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2011-0081date:2011-01-11T00:00:00
db:BIDid:45688date:2011-01-06T00:00:00