Multiple cross-site scripting (XSS) vulnerabilities in Jetdirect and the Embedded Web Server (EWS) on certain HP LaserJet and Color LaserJet printers, and HP Digital Senders, allow remote attackers to inject arbitrary web script or HTML via the (1) Product_URL or (2) Tech_URL parameter in an Apply action to the support_param.html/config script.

Project Subscriptions

Vendors Products
Cm8050 Mfp Subscribe
Cm8060 Mfp Subscribe
Color Laserjet 3000n Subscribe
Color Laserjet 3600n Subscribe
Color Laserjet 3800n Subscribe
Color Laserjet 4700n Subscribe
Color Laserjet 4730 Mfp Subscribe
Color Laserjet 6040 Mfp Subscribe
Color Laserjet Cm4730 Mfp Subscribe
Color Laserjet Cp3505 Subscribe
Color Laserjet Cp4005n Subscribe
Color Laserjet Cp6015 Subscribe
Ds 9200c Subscribe
Ds 9250c Subscribe
Laserjet 2410 Subscribe
Laserjet 2420 Subscribe
Laserjet 2430n Subscribe
Laserjet 4240 Subscribe
Laserjet 4250n Subscribe
Laserjet 4345 Mfp Subscribe
Laserjet 4350n Subscribe
Laserjet 5200n Subscribe
Laserjet 9040 Mfp Subscribe
Laserjet 9040n Subscribe
Laserjet 9050 Mfp Subscribe
Laserjet 9050n Subscribe
Laserjet M3027 Mfp Subscribe
Laserjet M3035 Mfp Subscribe
Laserjet M4345x Mfp Subscribe
Laserjet M5025 Mfp Subscribe
Laserjet M9040 Mpf Subscribe
Laserjet M9050 Mpf Subscribe
Laserjet P3005n Subscribe
Laserjet P4014 Subscribe
Laserjet P4515 Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2009-2677 Multiple cross-site scripting (XSS) vulnerabilities in Jetdirect and the Embedded Web Server (EWS) on certain HP LaserJet and Color LaserJet printers, and HP Digital Senders, allow remote attackers to inject arbitrary web script or HTML via the (1) Product_URL or (2) Tech_URL parameter in an Apply action to the support_param.html/config script.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-07T05:59:56.763Z

Reserved: 2009-08-05T00:00:00.000Z

Link: CVE-2009-2684

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2009-10-13T10:30:00.280

Modified: 2025-04-09T00:30:58.490

Link: CVE-2009-2684

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses