← Back

CVE-2009-4185

nvd nist
Published: Feb 5, 2010Modified: Apr 29, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:N/I:P/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

Cross-site scripting (XSS) vulnerability in proxy/smhui/getuiinfo in HP System Management Homepage (SMH) before 6.0 allows remote attackers to inject arbitrary web script or HTML via the servercert parameter.

Affected (37)

1 product
System Management Homepage
Configuration A
37 vulnerable
Vulnerable SoftwareAffected Versions
Hp
Up to 3.0.2.77
Version 2.0.0
Version 2.0.1
Version 2.0.2
Version 2.1.0-103
Version 2.1.0-103(a)
Version 2.1.0-109
Version 2.1.0-118
Version 2.1.10-186
Version 2.1.10
Version 2.1.11-197
Version 2.1.11
Version 2.1.12-118
Version 2.1.12-200
Version 2.1.15-210
Version 2.1.1
Version 2.1.2-127
Version 2.1.2
Version 2.1.3.132
Version 2.1.3
Version 2.1.4-143
Version 2.1.4
Version 2.1.5-146
Version 2.1.5
Version 2.1.6-156
Version 2.1.6
Version 2.1.7-168
Version 2.1.7
Version 2.1.8-177
Version 2.1.8
Version 2.1.9-178
Version 2.1.9
Version 2.1
Version 2.2.6
Version 2.2.8
Version 3.0.0-68
Version 3.0.1.73

References (14)

Source: hp-security-alert@hp.com
Vendor Advisory
Source: hp-security-alert@hp.com
Source: hp-security-alert@hp.com
Source: hp-security-alert@hp.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.