Short Name |
APP:HP-LASERJET-EWS-XSS |
---|---|
Severity |
Minor |
Recommended |
No |
Recommended Action |
Drop |
Category |
APP |
Keywords |
HP Laser Jet ews_functions Cross Site Scripting |
Release Date |
2014/09/22 |
Update Number |
2421 |
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-11.4+, srx-12.1+, srx-branch-12.1+, vmx-17.4+, vsrx-12.1+, vsrx3bsd-18.2+ |
This signature detects attempts to exploit a cross-site scripting vulnerability in the HP Laser Jet printers. It could lead to data stealing or data modification.
Multiple HP printers are prone to a directory-traversal vulnerability because the devices' webserver fails to sufficiently sanitize user-supplied input. Exploiting this issue will allow an attacker to view arbitrary local files within the context of the webserver. Information harvested may aid in launching further attacks. The following HP printer models are vulnerable: HP LaserJet MFP printers (all models with Printer Job Language (PJL) support), HP Color LaserJet MFP printers (all models with Printer Job Language (PJL) support), LaserJet 4100 series, 4200 series, 4300 series, 5100 series, 8150 series, and 9000 series.