exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

HP LaserJet Cross Site Scripting

HP LaserJet Cross Site Scripting
Posted Oct 8, 2009
Authored by Sh2kerr | Site dsecrg.com

Multiple security vulnerabilities have been identified with certain HP LaserJet printers, HP Color LaserJet printers and HP Digital Senders. The vulnerabilities could be exploited remotely by Cross Site Scripting (XSS).

tags | exploit, vulnerability, xss
advisories | CVE-2009-2684
SHA-256 | 032340f6ad00d3fd6574a58ec760211cc4ca9e551c56263295c9d5478714ff05

HP LaserJet Cross Site Scripting

Change Mirror Download
Digital Security Research Group [DSecRG] Advisory       #DSECRG-09-048

http://dsecrg.ru/pages/vul/show.php?id=148

Application: HP LaserJet printer web interface
Vulnerable: HP LaserJet 2200, 4350, 4600, 5500, and many others
Vendor URL: http://www.hp.com/
Bug: Multiple Stored XSS Vulnerabilities
Exploits: YES
Reported: 07.04.2009
Vendor response: 08.04.2009
Date of Public Advisory: 07.10.2009
CVE-number: CVE-2009-2684
CVSS2 score: 5.0 (AV:N/AC:L/Au:N/C:P/I:N/A:N)
Author: s.svistunovich, a.polyakov
Digital Security Research Group [DSecRG] (research [at] dsecrg [dot] com)



Description
***********
Multiple security vulnerabilities have been identified with certain HP LaserJet printers,
HP Color LaserJet printers and HP Digital Senders. The vulnerabilities could be exploited remotely by Cross Site Scripting (XSS).


Details
*******

Multiple Linked Stored XSS vulnerabilities found in script support_param.html/config

Attacker can inject XSS in parameters "Product_URL" and "Tech_URL".

After applying support parameters configuration (parameter "Apply") script code will inject in support page (support.htm).

Example:

http://[server]/support_param.html/config?Admin_Name=&Admin_Phone=&Product_URL=[XSS]&Tech_URL=[XSS]&Apply=Apply


Solution
********
wendor recomends the following steps can be taken to limit the exposure to the XSS vulnerabilities:

set the administrator password
use a new browser instance for administrator tasks
do not access other web sites while performing administrator tasks
exit the browser when administrator tasks are complete

Document ID: c01841397

HPSBPI02463 SSRT090061 rev.1 - HP LaserJet Printers, HP Color LaserJet Printers, Remote Cross Site Scripting (XSS)


http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01841397


References
**********

The Hewlett-Packard Company thanks Digital Security Research Group (dsecrg.com) for reporting these vulnerabilities to security-alert@hp.com.

http://dsecrg.ru/pages/vul/show.php?id=148
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01841397


About
*****

Digital Security is one of the leading IT security companies in CEMEA, providing information security consulting, audit and penetration testing services, risk analysis and ISMS-related services and certification for ISO/IEC 27001:2005 and PCI DSS standards. Digital Security Research Group focuses on web application and database security problems with vulnerability reports, advisories and whitepapers posted regularly on our website.


Contact: research [at] dsecrg [dot] com
http://www.dsecrg.com









Polyakov Alexandr
Information Security Analyst
______________________
DIGITAL SECURITY
phone: +7 812 703 1547
+7 812 430 9130
e-mail: a.polyakov@dsec.ru
www.dsec.ru


-----------------------------------
This message and any attachment are confidential and may be privileged or otherwise protected
from disclosure. If you are not the intended recipient any use, distribution, copying or disclosure
is strictly prohibited. If you have received this message in error, please notify the sender immediately
either by telephone or by e-mail and delete this message and any attachment from your system. Correspondence
via e-mail is for information purposes only. Digital Security neither makes nor accepts legally binding
statements by e-mail unless otherwise agreed.
-----------------------------------
Login or Register to add favorites

File Archive:

December 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Dec 1st
    0 Files
  • 2
    Dec 2nd
    41 Files
  • 3
    Dec 3rd
    25 Files
  • 4
    Dec 4th
    0 Files
  • 5
    Dec 5th
    0 Files
  • 6
    Dec 6th
    0 Files
  • 7
    Dec 7th
    0 Files
  • 8
    Dec 8th
    0 Files
  • 9
    Dec 9th
    0 Files
  • 10
    Dec 10th
    0 Files
  • 11
    Dec 11th
    0 Files
  • 12
    Dec 12th
    0 Files
  • 13
    Dec 13th
    0 Files
  • 14
    Dec 14th
    0 Files
  • 15
    Dec 15th
    0 Files
  • 16
    Dec 16th
    0 Files
  • 17
    Dec 17th
    0 Files
  • 18
    Dec 18th
    0 Files
  • 19
    Dec 19th
    0 Files
  • 20
    Dec 20th
    0 Files
  • 21
    Dec 21st
    0 Files
  • 22
    Dec 22nd
    0 Files
  • 23
    Dec 23rd
    0 Files
  • 24
    Dec 24th
    0 Files
  • 25
    Dec 25th
    0 Files
  • 26
    Dec 26th
    0 Files
  • 27
    Dec 27th
    0 Files
  • 28
    Dec 28th
    0 Files
  • 29
    Dec 29th
    0 Files
  • 30
    Dec 30th
    0 Files
  • 31
    Dec 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close