APP: HP Laser Jet ews_functions Cross Site Scripting

This signature detects attempts to exploit a cross-site scripting vulnerability in the HP Laser Jet printers. It could lead to data stealing or data modification.

Extended Description

Multiple HP printers are prone to a directory-traversal vulnerability because the devices' webserver fails to sufficiently sanitize user-supplied input. Exploiting this issue will allow an attacker to view arbitrary local files within the context of the webserver. Information harvested may aid in launching further attacks. The following HP printer models are vulnerable: HP LaserJet MFP printers (all models with Printer Job Language (PJL) support), HP Color LaserJet MFP printers (all models with Printer Job Language (PJL) support), LaserJet 4100 series, 4200 series, 4300 series, 5100 series, 8150 series, and 9000 series.

Affected Products

Hp laserjet_m1522n_mfp

References

BugTraq: 44882

CVE: CVE-2010-4107

Short Name
APP:HP-LASERJET-EWS-XSS
Severity
Minor
Recommended
False
Recommended Action
Drop
Category
APP
Keywords
CVE-2010-4107 Cross HP Jet Laser Scripting Site bid:44882 ews_functions
Release Date
09/22/2014
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3336
Port
tcp/9100
False Positive
Unknown
Vendors

Hp

CVSS Score

7.8

Found a potential security threat?