flip the script
Showing 1 - 1 of 1 RSS Feed

Files

secunia-snmp.txt
Posted Oct 20, 2008
Authored by Dyon Balding | Site secunia.com

Secunia Research has discovered a vulnerability in HP SiteScope, which can be exploited by malicious people to conduct script insertion attacks. The SiteScope server performs agent-less monitoring of the IT infrastructure and can be configured to receive SNMP traps from devices. The status of the SNMP monitor and the content of received SNMP trap messages can be viewed in the web interface. The received SNMP messages are rendered in the context of the management interface with no filtering or sanitizing. This can be exploited to execute arbitrary HTML and script code in a user's browser session when viewing the information. HP SiteScope 9.0 build 911 is affected.

tags | advisory, web, arbitrary
advisories | CVE-2007-4350
MD5 | 3848e94018cfac51342b670a2eb8ec73
Page 1 of 1
Back1Next

Top Authors In Last 30 Days

packet storm

© 2012 Packet Storm. All rights reserved.

close