CVE-2017-12544 XSS on HPE System Management Homepage v7.6.0.11 and minor

2018-03-05 Thread spinfoo
Product: HPE System Management Homepage Versions: 7.6.0.11 and minor versions Vulnerability: JavaScript Injection in file gsearch.php, parameter prod OWASP TOP 10: A1 Injection Type: Javascript Injection Impact: Allows an attacker to perform an XSS (Cross-Site Scripting) attack, execute arbitrary

CVE-2017-12544 XSS on HPE System Management Homepage v7.6.0.11 and minor

2018-03-02 Thread spinfoo
Product: HPE System Management Homepage Versions: 7.6.0.11 and minor versions Vulnerability: JavaScript Injection in file gsearch.php, parameter prod OWASP TOP 10: A1 Injection Type: Javascript Injection Impact: Allows an attacker to perform an XSS (Cross-Site Scripting) attack, execute arbitrary