« Volver al listado

CVE-2011-0280

Estado: ModificadaMedia (4.3)—

Multiple cross-site scripting (XSS) vulnerabilities in HP Power Manager (HPPM) 4.3.2 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the logType parameter to Contents/exportlogs.asp, (2) the Id parameter to Contents/pagehelp.asp, or the (3) SORTORD or (4) SORTCOL parameter to Contents/applicationlogs.asp. NOTE: some of these details are obtained from third party information.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2011-0280",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ]
  },
  "affected": [
    {
      "source": "hp-security-alert@hp.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2011-03-14T19:55:00.697",
  "references": [
    {
      "url": "http://archives.neohapsis.com/archives/bugtraq/2011-03/0111.html",
      "source": "hp-security-alert@hp.com"
    },
    {
      "url": "http://secunia.com/advisories/43058",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "hp-security-alert@hp.com"
    },
    {
      "url": "http://www.securityfocus.com/bid/46830",
      "source": "hp-security-alert@hp.com"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/66035",
      "source": "hp-security-alert@hp.com"
    },
    {
      "url": "http://archives.neohapsis.com/archives/bugtraq/2011-03/0111.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/43058",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/46830",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/66035",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Multiple cross-site scripting (XSS) vulnerabilities in HP Power Manager (HPPM) 4.3.2 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the logType parameter to Contents/exportlogs.asp, (2) the Id parameter to Contents/pagehelp.asp, or the (3) SORTORD or (4) SORTCOL parameter to Contents/applicationlogs.asp.  NOTE: some of these details are obtained from third party information."
    },
    {
      "lang": "es",
      "value": "Múltiples vulnerabilidades de ejecución de secuencias de comandos en sitios cruzados (XSS) en HP Power Manager(HPPM)v4.3.2 y anteriores, permite a atacantes remotos inyectar secuencias de comandos web o HTML a través de los parámetros  (1) logType de Contents/exportlogs.asp, (2) Id de Contents/pagehelp.asp, o (3) SORTORD o(4) SORTCOL de Contents/applicationlogs.asp.\r\nNOTA : algunos de estos detalles han sido obtenidos de información de terceros ."
    }
  ],
  "lastModified": "2026-06-16T23:27:08.540",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:hp:power_manager:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "63F6F47C-2BD0-4523-9CE9-2DF813DAD007",
              "versionEndIncluding": "4.3.2"
            },
            {
              "criteria": "cpe:2.3:a:hp:power_manager:4.2.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DCCE8F58-E1A8-4DFA-80B1-32BECDAF1811"
            },
            {
              "criteria": "cpe:2.3:a:hp:power_manager:4.2.6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3F4CA6CE-AF65-41E9-829D-1582E53086F5"
            },
            {
              "criteria": "cpe:2.3:a:hp:power_manager:4.2.7:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6710514E-9885-4B85-9491-2760C4038C58"
            },
            {
              "criteria": "cpe:2.3:a:hp:power_manager:4.2.8:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4EF7306F-BFC5-479E-B4AF-4DCAE01FE3F5"
            },
            {
              "criteria": "cpe:2.3:a:hp:power_manager:4.2.9:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "41DC512A-EE43-4690-9F0C-38A1E5E0FFBA"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "hp-security-alert@hp.com"
}