CVE-2009-2684
Last modified
CVE-2009-2684 is a vulnerability of currently unknown severity. Multiple cross-site scripting (XSS) vulnerabilities in Jetdirect and the Embedded Web Server (EWS) on certain HP LaserJet and Color LaserJet printers, and HP Digital Senders, allow remote attackers to inject arbitrary web script or HTML via the (1) Product_URL or (2) Tech_URL parameter in an Apply action to the support_param.html/config script.. EPSS estimates a 2.21% chance of exploitation in the next 30 days.
Description
Multiple cross-site scripting (XSS) vulnerabilities in Jetdirect and the Embedded Web Server (EWS) on certain HP LaserJet and Color LaserJet printers, and HP Digital Senders, allow remote attackers to inject arbitrary web script or HTML via the (1) Product_URL or (2) Tech_URL parameter in an Apply action to the support_param.html/config script.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Hp | Cm8050 Mfp | All versions |
| Hp | Cm8060 Mfp | All versions |
| Hp | Color Laserjet 3000n | All versions |
| Hp | Color Laserjet 3600n | All versions |
| Hp | Color Laserjet 3800n | All versions |
| Hp | Color Laserjet 4700n | All versions |
| Hp | Color Laserjet 4730 Mfp | All versions |
| Hp | Color Laserjet 6040 Mfp | All versions |
| Hp | Color Laserjet Cm4730 Mfp | All versions |
| Hp | Color Laserjet Cp3505 | All versions |
| Hp | Color Laserjet Cp4005n | All versions |
| Hp | Color Laserjet Cp6015 | All versions |
| Hp | Ds 9200c | All versions |
| Hp | Ds 9250c | All versions |
| Hp | Laserjet 2410 | All versions |
| Hp | Laserjet 2420 | All versions |
| Hp | Laserjet 2430n | All versions |
| Hp | Laserjet 4240 | All versions |
| Hp | Laserjet 4250n | All versions |
| Hp | Laserjet 4345 Mfp | All versions |
| Hp | Laserjet 4350n | All versions |
| Hp | Laserjet 5200n | All versions |
| Hp | Laserjet 9040 Mfp | All versions |
| Hp | Laserjet 9040n | All versions |
| Hp | Laserjet 9050 Mfp | All versions |
| Hp | Laserjet 9050n | All versions |
| Hp | Laserjet M3027 Mfp | All versions |
| Hp | Laserjet M3035 Mfp | All versions |
| Hp | Laserjet M4345x Mfp | All versions |
| Hp | Laserjet M5025 Mfp | All versions |
| Hp | Laserjet M9040 Mpf | All versions |
| Hp | Laserjet M9050 Mpf | All versions |
| Hp | Laserjet P3005n | All versions |
| Hp | Laserjet P4014 | All versions |
| Hp | Laserjet P4515 | All versions |
References
- http://secunia.com/advisories/36969Vendor Advisory
- http://www.vupen.com/english/advisories/2009/2850Vendor Advisory
- http://secunia.com/advisories/36969Vendor Advisory
- http://www.vupen.com/english/advisories/2009/2850Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2009-2684?
How severe is CVE-2009-2684?
How do I fix CVE-2009-2684?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2009
- CVE-2009-2678Unspecified vulnerability in Open System Services (OSS) Name…
- CVE-2009-2679Unspecified vulnerability in bootpd in HP HP-UX B.11.11, B.1…
- CVE-2009-2680Unspecified vulnerability in the Remote Management Interface…
- CVE-2009-2681Unspecified vulnerability in HP ProCurve Identity Driven Man…
- CVE-2009-2682Unspecified vulnerability in Role-Based Access Control (RBAC…
- CVE-2009-2683Unspecified vulnerability in the Sender module in HP Remote …
- CVE-2009-2685Stack-based buffer overflow in the login form in the managem…
- CVE-2009-2686Unspecified vulnerability in HP NonStop G06.12.00 through G0…
- CVE-2009-2687The exif_read_data function in the Exif module in PHP before…
- CVE-2009-2688Multiple integer overflows in glyphs-eimage.c in XEmacs 21.4…
- CVE-2009-2689JDK13Services.getProviders in Sun Java SE 5.0 before Update …
- CVE-2009-2690The encoder in Sun Java SE 6 before Update 15, and OpenJDK, …
Are you affected by CVE-2009-2684?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
