Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

Short Name

APP:HP-LASERJET-EWS-XSS

Severity

Medium

Recommended

No

Recommended Action

Drop

Category

APP

Keywords

HP Laser Jet ews_functions Cross Site Scripting

Release Date

2014/09/22

Update Number

2421

Supported Platforms

idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+

APP: HP Laser Jet ews_functions Cross Site Scripting


This signature detects attempts to exploit a cross-site scripting vulnerability in the HP Laser Jet printers. It could lead to data stealing or data modification.

Extended Description

Multiple HP printers are prone to a directory-traversal vulnerability because the devices' webserver fails to sufficiently sanitize user-supplied input. Exploiting this issue will allow an attacker to view arbitrary local files within the context of the webserver. Information harvested may aid in launching further attacks. The following HP printer models are vulnerable: HP LaserJet MFP printers (all models with Printer Job Language (PJL) support), HP Color LaserJet MFP printers (all models with Printer Job Language (PJL) support), LaserJet 4100 series, 4200 series, 4300 series, 5100 series, 8150 series, and 9000 series.

Affected Products

  • HP Color LaserJet 4730mfp
  • HP Color LaserJet 4730 MFP
  • HP Color LaserJet 6040 MFP
  • HP Color LaserJet 9500mfp
  • HP Color LaserJet CM4730 MFP
  • HP LaserJet 5100 Series
  • HP LaserJet 3035 MFP
  • HP LaserJet 4100
  • HP LaserJet 4100MFP
  • HP LaserJet 4200
  • HP LaserJet 4300
  • HP LaserJet 4345mfp
  • HP LaserJet 4345 MFP
  • HP LaserJet 5035 MFP
  • HP LaserJet 8150
  • HP LaserJet 9000
  • HP LaserJet 9000MFP
  • HP LaserJet 9050 MFP
  • HP LaserJet M1522n MFP
  • HP LaserJet M4345x MFP
  • HP LaserJet M9050 MFP

References

  • BugTraq: 44882
  • CVE: CVE-2010-4107

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out