vendor:
Mini-300PU & Mini100s Print Servers
by:
GotGeek Labs
8.8
CVSS
HIGH
Stored Cross-site Scripting
79
CWE
Product Name: Mini-300PU & Mini100s Print Servers
Affected Version From: 6.02.39P (ZOT-PS-39/6.2.0001)
Affected Version To: 8.03.30P 0007 (ZOT-PS-30/8.3.0007)
Patch Exists: YES
Related CWE: N/A
CPE: //a:planex:mini-300pu_print_server
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 2000/XP, Linux, Mac OS 8.1, Unix, Netware
2011
Planex Mini-300PU & Mini100s Cross-site Scripting Vulnerability
Web interface from Mini-300PU and Mini100s Print Servers are affected by stored cross-site scripting vulnerability because it fails to properly sanitize user-supplied input at 'NDSContext' field in 'NetWare NDS Settings' area. An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. After injecting the XSS code, you need to access Netware status page.
Mitigation:
Input validation should be used to prevent the introduction of malicious code into the application.