PT-2010-5302 · Hewlett Packard · Hp Laserjet Mfp+7

Moritz Jodeit

·

Publicado

2010-11-17

·

Atualizado

2017-08-17

·

CVE-2010-4107

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions HP LaserJet MFP printers, Color LaserJet MFP printers, and LaserJet 4100, 4200, 4300, 5100, 8150, and 9000 printers (affected versions not specified)
Description The default configuration of the PJL Access value in the File System External Access settings enables PJL commands that use the device's filesystem. This allows remote attackers to read arbitrary files via a command inside a print job, as demonstrated by a directory traversal attack.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2010-4107

Produtos afetados

Color Laserjet Mfp
Hp Laserjet Mfp
Laserjet 4100
Hp Laserjet 4200
Hp Laserjet 4300
Laserjet 5100
Laserjet 8150
Laserjet 9000