|
|
|
|
| |
Credit:
The original article can be found at: http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01034748
|
| |
Vulnerable Systems:
* System Management Homepage Version 2.0.0 through Version 2.0.2 for Microsoft Windows 2000
* System Management Homepage Version 2.0.0 through Version 2.0.2 for Microsoft Windows Server 2003
* System Management Homepage Version 2.0.0 through Version 2.0.2 for Microsoft Windows Server 2003 x64 Edition
* System Management Homepage Version 2.0.0 through Version 2.0.2 for Microsoft Windows Server 2003 64-bit
* System Management Homepage Version 2.0.0 through Version 2.0.2 for Linux
Potential security vulnerability has been identified with HP System Management Homepage running PHP. These vulnerabilities could be exploited remotely to allow Cross Site Scripting , to create a Denial of Service, or to execute arbitrary code.
Patch Availability:
HP has made the following software updates available to resolve the vulnerability:
The latest updates are available from: http://h18013.www1.hp.com/products/servers/management/agents/index.html
CVE Information:
CVE-2004-1019
CVE-2004-1020
CVE-2004-1063
CVE-2004-1064
CVE-2004-1065
Disclosure Timeline:
Release Date: 2005-09-21
Last Updated: 2010-08-30
|
|
|
|
|