4.3

CVE-2010-4111

Cross-site scripting (XSS) vulnerability in HP Insight Diagnostics Online Edition before 8.5.1.3712 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Data is provided by the National Vulnerability Database (NVD)
HpInsight Diagnostics Editiononline Version <= 8.5.0.3625
   MicrosoftWindows
HpInsight Diagnostics Version6.3.0.878 Editiononline
   MicrosoftWindows
HpInsight Diagnostics Version6.3.1.887 Editiononline
   MicrosoftWindows
HpInsight Diagnostics Version7.0.0.1198 Editiononline
   MicrosoftWindows
HpInsight Diagnostics Version7.0.1.1219 Editiononline
   MicrosoftWindows
HpInsight Diagnostics Version7.4.0.1570 Editiononline
   MicrosoftWindows
HpInsight Diagnostics Version7.5.0.1679 Editiononline
   MicrosoftWindows
HpInsight Diagnostics Version7.5.5.1681 Editiononline
   MicrosoftWindows
HpInsight Diagnostics Version7.6.0.1984 Editiononline
   MicrosoftWindows
HpInsight Diagnostics Version7.7.0.2112 Editiononline
   MicrosoftWindows
HpInsight Diagnostics Version7.8.0.2257 Editiononline
   MicrosoftWindows
HpInsight Diagnostics Version7.9.0.2359 Editiononline
   MicrosoftWindows
HpInsight Diagnostics Version7.9.1.2401 Editiononline
   MicrosoftWindows
HpInsight Diagnostics Version8.0.0.2587 Editiononline
   MicrosoftWindows
HpInsight Diagnostics Version8.1.0.2718 Editiononline
   MicrosoftWindows
HpInsight Diagnostics Version8.1.1.2784 Editiononline
   MicrosoftWindows
HpInsight Diagnostics Version8.1.5.2890 Editiononline
   MicrosoftWindows
HpInsight Diagnostics Version8.2.0.3058 Editiononline
   MicrosoftWindows
HpInsight Diagnostics Version8.2.5.3157 Editiononline
   MicrosoftWindows
HpInsight Diagnostics Version8.3.0.3320 Editiononline
   MicrosoftWindows
HpInsight Diagnostics Version8.4.0.3521 Editiononline
   MicrosoftWindows
HpInsight Diagnostics Editiononline Version <= 8.5.0-11
   LinuxLinux Kernel
HpInsight Diagnostics Version6.3.0-15 Editiononline
   LinuxLinux Kernel
HpInsight Diagnostics Version6.3.1-1 Editiononline
   LinuxLinux Kernel
HpInsight Diagnostics Version7.0.0-30 Editiononline
   LinuxLinux Kernel
HpInsight Diagnostics Version7.0.1-8 Editiononline
   LinuxLinux Kernel
HpInsight Diagnostics Version7.4.0-11 Editiononline
   LinuxLinux Kernel
HpInsight Diagnostics Version7.5.0-14 Editiononline
   LinuxLinux Kernel
HpInsight Diagnostics Version7.5.5-1 Editiononline
   LinuxLinux Kernel
HpInsight Diagnostics Version7.6.0-23 Editiononline
   LinuxLinux Kernel
HpInsight Diagnostics Version7.7.0-142 Editiononline
   LinuxLinux Kernel
HpInsight Diagnostics Version7.8.0-159 Editiononline
   LinuxLinux Kernel
HpInsight Diagnostics Version7.9.0-105 Editiononline
   LinuxLinux Kernel
HpInsight Diagnostics Version7.9.1-15 Editiononline
   LinuxLinux Kernel
HpInsight Diagnostics Version8.0.0-210 Editiononline
   LinuxLinux Kernel
HpInsight Diagnostics Version8.1.0-136 Editiononline
   LinuxLinux Kernel
HpInsight Diagnostics Version8.1.1-206 Editiononline
   LinuxLinux Kernel
HpInsight Diagnostics Version8.1.5-311 Editiononline
   LinuxLinux Kernel
HpInsight Diagnostics Version8.3.0-14 Editiononline
   LinuxLinux Kernel
HpInsight Diagnostics Version8.3.1-105 Editiononline
   LinuxLinux Kernel
HpInsight Diagnostics Version8.4.0-18 Editiononline
   LinuxLinux Kernel
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.48% 0.638
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.