CVE-2011-0280: XSS
Multiple cross-site scripting (XSS) vulnerabilities in HP Power Manager (HPPM) 4.3.2 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the logType parameter to Contents/exportlogs.asp, (2) the Id parameter to Contents/pagehelp.asp, or the (3) SORTORD or (4) SORTCOL parameter to Contents/applicationlogs.asp. NOTE: some of these details are obtained from third party information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-0280?
CVE-2011-0280 is classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2011-0280?
To fix CVE-2011-0280, upgrade HP Power Manager to version 4.3.3 or later, which addresses the identified XSS vulnerabilities.
What could attackers do with CVE-2011-0280?
Attackers exploiting CVE-2011-0280 could inject arbitrary web scripts or HTML, potentially leading to session hijacking or data theft.
What versions of HP Power Manager are affected by CVE-2011-0280?
CVE-2011-0280 affects HP Power Manager versions 4.3.2 and earlier, including versions 4.2.5 through 4.2.9.
Is CVE-2011-0280 a client-side or server-side vulnerability?
CVE-2011-0280 is primarily a client-side vulnerability, allowing attackers to execute scripts in the context of a user’s browser.