First published: Mon Oct 13 2008(Updated: )
Cross-site scripting (XSS) vulnerability in HP System Management Homepage (SMH) before 2.1.15.210 on Linux and Windows allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2008-1663.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
HP System Management Homepage | =2.1.9-178 | |
HP System Management Homepage | =2.1.2-127 | |
HP System Management Homepage | =2.1.11-197 | |
HP System Management Homepage | =2.1.2 | |
HP System Management Homepage | =2.1.6 | |
HP System Management Homepage | =2.0.2 | |
HP System Management Homepage | =2.1.8-177 | |
HP System Management Homepage | =2.1.4-143 | |
HP System Management Homepage | =2.1.0-103 | |
HP System Management Homepage | =2.1.11 | |
HP System Management Homepage | =2.1.12-118 | |
HP System Management Homepage | =2.1.1 | |
HP System Management Homepage | =2.1.8 | |
HP System Management Homepage | <=2.1.12-200 | |
HP System Management Homepage | =2.0.0 | |
HP System Management Homepage | =2.1.0-103\(a\) | |
HP System Management Homepage | =2.0.1 | |
HP System Management Homepage | =2.1.0-109 | |
HP System Management Homepage | =2.1.5-146 | |
HP System Management Homepage | =2.1.0-118 | |
HP System Management Homepage | =2.1.9 | |
HP System Management Homepage | =2.1.5 | |
HP System Management Homepage | =2.1.3 | |
HP System Management Homepage | =2.1.3.132 | |
HP System Management Homepage | =2.1.7 | |
HP System Management Homepage | =2.1.6-156 | |
HP System Management Homepage | =2.1.7-168 | |
HP System Management Homepage | =2.1.10 | |
HP System Management Homepage | =2.1 | |
HP System Management Homepage | =2.1.10-186 | |
HP System Management Homepage | =2.1.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-4411 has a high severity due to its potential for allowing remote attackers to inject malicious scripts.
To fix CVE-2008-4411, upgrade to HP System Management Homepage version 2.1.15.210 or later.
CVE-2008-4411 affects multiple versions prior to 2.1.15.210, including 2.1.9-178 and earlier versions.
CVE-2008-4411 enables cross-site scripting (XSS) attacks, allowing attackers to inject arbitrary web script or HTML.
Yes, both Linux and Windows versions of HP System Management Homepage are affected by CVE-2008-4411.