ID

VAR-201501-0136


CVE

CVE-2015-1056


TITLE

Brother MFC-J4410DW Cross-site scripting vulnerability in printer firmware

Trust: 0.8

sources: JVNDB: JVNDB-2015-001056

DESCRIPTION

Cross-site scripting (XSS) vulnerability in Brother MFC-J4410DW printer with firmware before L allows remote attackers to inject arbitrary web script or HTML via the url parameter to general/status.html and possibly other pages. The Brother MFC-J4410DW is a color laser printer device that supports wireless network printing. An attacker could exploit these vulnerabilities to execute arbitrary script code in the context of a browser that is not known to the affected user. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks. Brother MFC-J4410DW is a printer product of Japan Brother Industries (Brother). The vulnerability is caused by the general/status.html file not adequately filtering the 'url' parameter

Trust: 2.52

sources: NVD: CVE-2015-1056 // JVNDB: JVNDB-2015-001056 // CNVD: CNVD-2015-00187 // BID: 71911 // VULHUB: VHN-79016

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2015-00187

AFFECTED PRODUCTS

vendor:brothermodel:mfc-j4410dwscope:eqversion:*

Trust: 1.0

vendor:brothermodel:mfc-j4410dwscope:lteversion:k

Trust: 1.0

vendor:brother industrymodel:mfc-j4410dwscope: - version: -

Trust: 0.8

vendor:brother industrymodel:mfc-j4410dwscope:ltversion:l

Trust: 0.8

vendor:brothermodel:industries ltd mfc-j4410dwscope: - version: -

Trust: 0.6

vendor:brothermodel:mfc-j4410dwscope:eqversion:k

Trust: 0.6

vendor:brothermodel:mfc-j4410dwscope:eqversion:0

Trust: 0.3

sources: CNVD: CNVD-2015-00187 // BID: 71911 // JVNDB: JVNDB-2015-001056 // CNNVD: CNNVD-201501-180 // NVD: CVE-2015-1056

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2015-1056
value: MEDIUM

Trust: 1.0

NVD: CVE-2015-1056
value: MEDIUM

Trust: 0.8

CNVD: CNVD-2015-00187
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-201501-180
value: MEDIUM

Trust: 0.6

VULHUB: VHN-79016
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2015-1056
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2015-00187
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

VULHUB: VHN-79016
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: CNVD: CNVD-2015-00187 // VULHUB: VHN-79016 // JVNDB: JVNDB-2015-001056 // CNNVD: CNNVD-201501-180 // NVD: CVE-2015-1056

PROBLEMTYPE DATA

problemtype:CWE-79

Trust: 1.9

sources: VULHUB: VHN-79016 // JVNDB: JVNDB-2015-001056 // NVD: CVE-2015-1056

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201501-180

TYPE

XSS

Trust: 0.6

sources: CNNVD: CNNVD-201501-180

CONFIGURATIONS

sources: JVNDB: JVNDB-2015-001056

PATCH

title:Top Pageurl:http://www.brother.com

Trust: 0.8

title:There are multiple cross-site scripting vulnerability patches for the Brother MFC-J4410DW printer 'url' parameterurl:https://www.cnvd.org.cn/patchInfo/show/53781

Trust: 0.6

sources: CNVD: CNVD-2015-00187 // JVNDB: JVNDB-2015-001056

EXTERNAL IDS

db:NVDid:CVE-2015-1056

Trust: 2.8

db:BIDid:71911

Trust: 2.6

db:PACKETSTORMid:129841

Trust: 2.5

db:JVNDBid:JVNDB-2015-001056

Trust: 0.8

db:CNNVDid:CNNVD-201501-180

Trust: 0.7

db:CNVDid:CNVD-2015-00187

Trust: 0.6

db:XFid:99906

Trust: 0.6

db:VULHUBid:VHN-79016

Trust: 0.1

sources: CNVD: CNVD-2015-00187 // VULHUB: VHN-79016 // BID: 71911 // JVNDB: JVNDB-2015-001056 // CNNVD: CNNVD-201501-180 // NVD: CVE-2015-1056

REFERENCES

url:http://packetstormsecurity.com/files/129841/brother-mfc-j4410dw-cross-site-scripting.html

Trust: 2.5

url:http://www.securityfocus.com/bid/71911

Trust: 2.3

url:http://www.securityfocus.com/archive/1/534398/100/0/threaded

Trust: 1.1

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/99906

Trust: 1.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2015-1056

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2015-1056

Trust: 0.8

url:http://www.securityfocus.com/archive/1/archive/1/534398/100/0/threaded

Trust: 0.6

url:http://xforce.iss.net/xforce/xfdb/99906

Trust: 0.6

url:http://www.brother.com

Trust: 0.3

url:http://seclists.org/bugtraq/2015/jan/19

Trust: 0.3

sources: CNVD: CNVD-2015-00187 // VULHUB: VHN-79016 // BID: 71911 // JVNDB: JVNDB-2015-001056 // CNNVD: CNNVD-201501-180 // NVD: CVE-2015-1056

CREDITS

Dave Daly of Dionach

Trust: 0.9

sources: BID: 71911 // CNNVD: CNNVD-201501-180

SOURCES

db:CNVDid:CNVD-2015-00187
db:VULHUBid:VHN-79016
db:BIDid:71911
db:JVNDBid:JVNDB-2015-001056
db:CNNVDid:CNNVD-201501-180
db:NVDid:CVE-2015-1056

LAST UPDATE DATE

2025-04-13T23:35:12.946000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2015-00187date:2015-01-09T00:00:00
db:VULHUBid:VHN-79016date:2018-10-09T00:00:00
db:BIDid:71911date:2015-04-13T21:01:00
db:JVNDBid:JVNDB-2015-001056date:2015-01-21T00:00:00
db:CNNVDid:CNNVD-201501-180date:2015-01-19T00:00:00
db:NVDid:CVE-2015-1056date:2025-04-12T10:46:40.837

SOURCES RELEASE DATE

db:CNVDid:CNVD-2015-00187date:2015-01-09T00:00:00
db:VULHUBid:VHN-79016date:2015-01-16T00:00:00
db:BIDid:71911date:2015-01-07T00:00:00
db:JVNDBid:JVNDB-2015-001056date:2015-01-21T00:00:00
db:CNNVDid:CNNVD-201501-180date:2015-01-09T00:00:00
db:NVDid:CVE-2015-1056date:2015-01-16T15:59:06.077