Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

This site is deprecated. Please CLICK HERE for latest updates

Short Name

APP:HP-LASERJET-EWS-XSS

Severity

Minor

Recommended

No

Recommended Action

Drop

Category

APP

Keywords

HP Laser Jet ews_functions Cross Site Scripting

Release Date

2014/09/22

Update Number

2421

Supported Platforms

idp-4.0+, isg-3.0+, j-series-9.5+, mx-11.4+, srx-12.1+, srx-branch-12.1+, vmx-17.4+, vsrx-12.1+, vsrx3bsd-18.2+

APP: HP Laser Jet ews_functions Cross Site Scripting


This signature detects attempts to exploit a cross-site scripting vulnerability in the HP Laser Jet printers. It could lead to data stealing or data modification.

Extended Description

Multiple HP printers are prone to a directory-traversal vulnerability because the devices' webserver fails to sufficiently sanitize user-supplied input. Exploiting this issue will allow an attacker to view arbitrary local files within the context of the webserver. Information harvested may aid in launching further attacks. The following HP printer models are vulnerable: HP LaserJet MFP printers (all models with Printer Job Language (PJL) support), HP Color LaserJet MFP printers (all models with Printer Job Language (PJL) support), LaserJet 4100 series, 4200 series, 4300 series, 5100 series, 8150 series, and 9000 series.

Affected Products

  • Hp color_laserjet_4730mfp
  • Hp color_laserjet_4730_mfp
  • Hp color_laserjet_6040_mfp
  • Hp color_laserjet_9500mfp
  • Hp color_laserjet_cm4730_mfp
  • Hp laserjet 5100 Series
  • Hp laserjet_3035_mfp
  • Hp laserjet_4100
  • Hp laserjet_4100mfp
  • Hp laserjet_4200
  • Hp laserjet_4300
  • Hp laserjet_4345mfp
  • Hp laserjet_4345_mfp
  • Hp laserjet_5035_mfp
  • Hp laserjet_8150
  • Hp laserjet_9000
  • Hp laserjet_9000mfp
  • Hp laserjet_9050_mfp
  • Hp laserjet_m1522n_mfp
  • Hp laserjet_m4345x_mfp
  • Hp laserjet_m9050_mfp

References

  • BugTraq: 44882
  • CVE: CVE-2010-4107

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out