CVE-2009-4185: XSS
Cross-site scripting (XSS) vulnerability in proxy/smhui/getuiinfo in HP System Management Homepage (SMH) before 6.0 allows remote attackers to inject arbitrary web script or HTML via the servercert parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-4185?
CVE-2009-4185 is classified as a moderate severity vulnerability due to its potential for cross-site scripting (XSS) attacks.
How do I fix CVE-2009-4185?
To fix CVE-2009-4185, you should update your HP System Management Homepage to version 6.0 or later.
What versions of HP System Management Homepage are affected by CVE-2009-4185?
CVE-2009-4185 affects multiple versions of HP System Management Homepage before 6.0, including versions 2.0.0 to 3.0.2.77.
What type of vulnerability is CVE-2009-4185?
CVE-2009-4185 is a cross-site scripting (XSS) vulnerability allowing attackers to inject arbitrary web scripts or HTML.
Can CVE-2009-4185 be exploited remotely?
Yes, CVE-2009-4185 can be exploited remotely by attackers to execute malicious scripts in the context of the user's browser.