vendor:
Multiple Print Servers
by:
GotGeek Labs
8.8
CVSS
HIGH
Stored Cross-site Scripting
79
CWE
Product Name: Multiple Print Servers
Affected Version From: 8.03.30F 0016 (ZOT-PS-30/8.3.0016)
Affected Version To: 6.03.39F 0007 (ZOT-PS-39/6.3.0007)
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2011
ZO Tech Multiple Print Servers Cross-site Scripting Vulnerability
Web interface from PA101, PU201, PA301 and PS531 Print Servers are affected by stored cross-site scripting vulnerability because it fails to properly sanitize user-supplied input at 'NDSContext' field in 'NetWare NDS Settings' area. An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site.
Mitigation:
Input validation should be used to prevent the execution of malicious scripts.