4.3
CVSSv2

CVE-2010-4111

Published: 22/12/2010 Updated: 11/01/2011
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in HP Insight Diagnostics Online Edition prior to 8.5.1.3712 allows remote malicious users to inject arbitrary web script or HTML via unspecified vectors.

Vulnerable Product Search on Vulmon Subscribe to Product

hp insight_diagnostics 8.3.0.3320

hp insight_diagnostics 8.2.5.3157

hp insight_diagnostics 7.9.0.2359

hp insight_diagnostics 7.8.0.2257

hp insight_diagnostics 7.0.0.1198

hp insight_diagnostics 6.3.1.887

hp insight_diagnostics

hp insight_diagnostics 8.4.0.3521

hp insight_diagnostics 8.0.0.2587

hp insight_diagnostics 7.9.1.2401

hp insight_diagnostics 7.4.0.1570

hp insight_diagnostics 7.0.1.1219

hp insight_diagnostics 8.2.0.3058

hp insight_diagnostics 8.1.5.2890

hp insight_diagnostics 7.7.0.2112

hp insight_diagnostics 7.6.0.1984

hp insight_diagnostics 6.3.0.878

hp insight_diagnostics 8.1.1.2784

hp insight_diagnostics 8.1.0.2718

hp insight_diagnostics 7.5.5.1681

hp insight_diagnostics 7.5.0.1679

hp insight_diagnostics 8.3.0-14

hp insight_diagnostics 8.1.5-311

hp insight_diagnostics 7.7.0-142

hp insight_diagnostics 7.6.0-23

hp insight_diagnostics 6.3.0-15

hp insight_diagnostics 8.4.0-18

hp insight_diagnostics 8.3.1-105

hp insight_diagnostics 7.9.0-105

hp insight_diagnostics 7.8.0-159

hp insight_diagnostics 7.0.0-30

hp insight_diagnostics 6.3.1-1

hp insight_diagnostics 8.1.1-206

hp insight_diagnostics 8.1.0-136

hp insight_diagnostics 7.5.5-1

hp insight_diagnostics 7.5.0-14

hp insight_diagnostics 8.0.0-210

hp insight_diagnostics 7.9.1-15

hp insight_diagnostics 7.4.0-11

hp insight_diagnostics 7.0.1-8

Exploits

source: wwwsecurityfocuscom/bid/45420/info HP Insight Diagnostics Online Edition is prone to multiple cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected si ...
HP System Management Homepage suffers from multiple cross site scripting vulnerabilities ...