vendor:
Intelligent Management Center
by:
Hewlett Packard
5,5
CVSS
MEDIUM
Reflective XSS and Information Disclosure
79 (Cross-site Scripting (XSS))
CWE
Product Name: Intelligent Management Center
Affected Version From: 3.3.9 R2 606 29 Sept 2009
Affected Version To: 3.3 SP1 R2 606 15 Dec 2009
Patch Exists: YES
Related CWE: N/A
CPE: a:3com:intelligent_management_center
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows, Microsoft SQL 2005
2010
PR10-02: Various XSS and information disclosure flaws within 3Com* iMC (Intelligent Management Center)
3Com's iMC (Intelligent Management Centre) provides professional management of 3Com and third party network devices, the IMC is normally accessed using a web browser over port 8080. Various IMC pages are vulnerable to a reflective XSS attack, including the login page. Various pages also disclose information including the SQL sa account password which might be used to assist in carrying out further attacks.
Mitigation:
Ensure that all user-supplied input is validated and sanitized before being used in the application. Ensure that all output is properly encoded before being sent to the client.