CVE-2009-2684
Last modified
CVE-2009-2684 is a vulnerability of currently unknown severity. Multiple cross-site scripting (XSS) vulnerabilities in Jetdirect and the Embedded Web Server (EWS) on certain HP LaserJet and Color LaserJet printers, and HP Digital Senders, allow remote attackers to inject arbitrary web script or HTML via the (1) Product_URL or (2) Tech_URL parameter in an Apply action to the support_param.html/config script.. EPSS estimates a 2.21% chance of exploitation in the next 30 days.
Description
Multiple cross-site scripting (XSS) vulnerabilities in Jetdirect and the Embedded Web Server (EWS) on certain HP LaserJet and Color LaserJet printers, and HP Digital Senders, allow remote attackers to inject arbitrary web script or HTML via the (1) Product_URL or (2) Tech_URL parameter in an Apply action to the support_param.html/config script.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Hp | Cm8050 Mfp | All versions |
| Hp | Cm8060 Mfp | All versions |
| Hp | Color Laserjet 3000n | All versions |
| Hp | Color Laserjet 3600n | All versions |
| Hp | Color Laserjet 3800n | All versions |
| Hp | Color Laserjet 4700n | All versions |
| Hp | Color Laserjet 4730 Mfp | All versions |
| Hp | Color Laserjet 6040 Mfp | All versions |
| Hp | Color Laserjet Cm4730 Mfp | All versions |
| Hp | Color Laserjet Cp3505 | All versions |
| Hp | Color Laserjet Cp4005n | All versions |
| Hp | Color Laserjet Cp6015 | All versions |
| Hp | Ds 9200c | All versions |
| Hp | Ds 9250c | All versions |
| Hp | Laserjet 2410 | All versions |
| Hp | Laserjet 2420 | All versions |
| Hp | Laserjet 2430n | All versions |
| Hp | Laserjet 4240 | All versions |
| Hp | Laserjet 4250n | All versions |
| Hp | Laserjet 4345 Mfp | All versions |
| Hp | Laserjet 4350n | All versions |
| Hp | Laserjet 5200n | All versions |
| Hp | Laserjet 9040 Mfp | All versions |
| Hp | Laserjet 9040n | All versions |
| Hp | Laserjet 9050 Mfp | All versions |
| Hp | Laserjet 9050n | All versions |
| Hp | Laserjet M3027 Mfp | All versions |
| Hp | Laserjet M3035 Mfp | All versions |
| Hp | Laserjet M4345x Mfp | All versions |
| Hp | Laserjet M5025 Mfp | All versions |
| Hp | Laserjet M9040 Mpf | All versions |
| Hp | Laserjet M9050 Mpf | All versions |
| Hp | Laserjet P3005n | All versions |
| Hp | Laserjet P4014 | All versions |
| Hp | Laserjet P4515 | All versions |
References
- http://secunia.com/advisories/36969Vendor Advisory
- http://www.vupen.com/english/advisories/2009/2850Vendor Advisory
- http://secunia.com/advisories/36969Vendor Advisory
- http://www.vupen.com/english/advisories/2009/2850Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2009-2684?
How severe is CVE-2009-2684?
How do I fix CVE-2009-2684?
Are you affected by CVE-2009-2684?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
