Multiple cross-site scripting (XSS) vulnerabilities in Jetdirect and the Embedded Web Server (EWS) on certain HP LaserJet and Color LaserJet printers, and HP Digital Senders, allow remote attackers to inject arbitrary web script or HTML via the (1) Product_URL or (2) Tech_URL parameter in an Apply action to the support_param.html/config script.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Hp
Subscribe
|
Cm8050 Mfp
Subscribe
Cm8060 Mfp
Subscribe
Color Laserjet 3000n
Subscribe
Color Laserjet 3600n
Subscribe
Color Laserjet 3800n
Subscribe
Color Laserjet 4700n
Subscribe
Color Laserjet 4730 Mfp
Subscribe
Color Laserjet 6040 Mfp
Subscribe
Color Laserjet Cm4730 Mfp
Subscribe
Color Laserjet Cp3505
Subscribe
Color Laserjet Cp4005n
Subscribe
Color Laserjet Cp6015
Subscribe
Ds 9200c
Subscribe
Ds 9250c
Subscribe
Laserjet 2410
Subscribe
Laserjet 2420
Subscribe
Laserjet 2430n
Subscribe
Laserjet 4240
Subscribe
Laserjet 4250n
Subscribe
Laserjet 4345 Mfp
Subscribe
Laserjet 4350n
Subscribe
Laserjet 5200n
Subscribe
Laserjet 9040 Mfp
Subscribe
Laserjet 9040n
Subscribe
Laserjet 9050 Mfp
Subscribe
Laserjet 9050n
Subscribe
Laserjet M3027 Mfp
Subscribe
Laserjet M3035 Mfp
Subscribe
Laserjet M4345x Mfp
Subscribe
Laserjet M5025 Mfp
Subscribe
Laserjet M9040 Mpf
Subscribe
Laserjet M9050 Mpf
Subscribe
Laserjet P3005n
Subscribe
Laserjet P4014
Subscribe
Laserjet P4515
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2009-2677 | Multiple cross-site scripting (XSS) vulnerabilities in Jetdirect and the Embedded Web Server (EWS) on certain HP LaserJet and Color LaserJet printers, and HP Digital Senders, allow remote attackers to inject arbitrary web script or HTML via the (1) Product_URL or (2) Tech_URL parameter in an Apply action to the support_param.html/config script. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-07T05:59:56.763Z
Reserved: 2009-08-05T00:00:00.000Z
Link: CVE-2009-2684
No data.
Status : Deferred
Published: 2009-10-13T10:30:00.280
Modified: 2025-04-09T00:30:58.490
Link: CVE-2009-2684
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD