vendor:
FPS-1101 10/100Mbps Direct Attached Print Server
by:
GotGeek Labs
7.5
CVSS
HIGH
Stored Cross-site Scripting
79
CWE
Product Name: FPS-1101 10/100Mbps Direct Attached Print Server
Affected Version From: 8.03.30A 0013 (ZOT-PS-30/8.3.0013)
Affected Version To: 8.03.30A 0007 (ZOT-PS-30/8.3.0007)
Patch Exists: YES
Related CWE: N/A
CPE: ZOT-PS-30/8.3.0013 -WWW-Authenticate
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2011
Planet FPS-1101 Cross-site Scripting Vulnerability
Web interface from FPS-1101 Print Server is affected by stored cross-site scripting vulnerability because it fails to properly sanitize user-supplied input at 'NDSContext' field in 'NetWare NDS Settings' area. An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. After injecting the XSS code, you need to access Netware status page.
Mitigation:
Upgrade to the latest version.