PT-2002-3134 · Compaq · Compaq Insight Management Agent

Published

2002-12-31

·

Updated

2008-09-05

·

CVE-2002-2422

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Compaq Insight Management Agents versions 2.0 through 4.3.7
Description The issue allows remote attackers to inject arbitrary web script or HTML via a URL. This injection can insert the script into the resulting error message, potentially leading to cross-site scripting (XSS) attacks.
Recommendations For Compaq Insight Management Agents versions 2.0 through 4.3.7, consider disabling the web interface or restricting access to it until a fix is available. Avoid using URLs that could inject arbitrary web script or HTML.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2002-2422

Affected Products

Compaq Insight Management Agent