CVE-2009-2684: XSS
Multiple cross-site scripting (XSS) vulnerabilities in Jetdirect and the Embedded Web Server (EWS) on certain HP LaserJet and Color LaserJet printers, and HP Digital Senders, allow remote attackers to inject arbitrary web script or HTML via the (1) ProductURL or (2) TechURL parameter in an Apply action to the supportparam.html/config script.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-2684?
CVE-2009-2684 has been categorized with a high severity due to the potential for remote code execution through cross-site scripting (XSS).
How do I fix CVE-2009-2684?
To fix CVE-2009-2684, update the firmware of the affected HP LaserJet printers and Digital Senders to the latest version provided by HP.
What products are affected by CVE-2009-2684?
CVE-2009-2684 affects various HP LaserJet and Color LaserJet printers, as well as HP Digital Senders, including models like LaserJet 5200n and Color LaserJet CP3505.
What type of attack can exploit CVE-2009-2684?
CVE-2009-2684 can be exploited via cross-site scripting (XSS), allowing attackers to inject malicious scripts into web pages viewed by users.
Is CVE-2009-2684 publicly known?
Yes, CVE-2009-2684 is a publicly known vulnerability that was disclosed in 2009.