---------------------------------------------------------------------- To improve our services to our customers, we have made a number of additions to the Secunia Advisories and have started translating the advisories to German. The improvements will help our customers to get a better understanding of how we reached our conclusions, how it was rated, our thoughts on exploitation, attack vectors, and scenarios. This includes: * Reason for rating * Extended description * Extended solution * Exploit code or links to exploit code * Deep links Read the full description: http://corporate.secunia.com/products/48/?r=l Contact Secunia Sales for more information: http://corporate.secunia.com/how_to_buy/15/?r=l ---------------------------------------------------------------------- TITLE: HP System Management Homepage PHP Multiple Vulnerabilities SECUNIA ADVISORY ID: SA22691 VERIFY ADVISORY: http://secunia.com/advisories/22691/ CRITICAL: Moderately critical IMPACT: Security Bypass, Cross Site Scripting, DoS, System access WHERE: >From remote SOFTWARE: HP System Management Homepage 2.x http://secunia.com/product/5490/ DESCRIPTION: HP has acknowledged some vulnerabilities in HP System Management Homepage, which can be exploited by malicious people to conduct cross-site scripting attacks, bypass certain security restrictions, and potentially compromise a vulnerable system. For more information: SA17371 The vulnerabilities are reported in versions prior to 2.1.5 on Linux and Windows. SOLUTION: Update to version 2.1.5. HP System Management Homepage for Linux (x86): Update to version 2.1.5-146. http://h18023.www1.hp.com/support/files/server/us/download/24193.html HP System Management Homepage for Linux (AMD64/EM64T): Update to version 2.1.5-146. http://h18023.www1.hp.com/support/files/server/us/download/24172.html HP System Management Homepage for Windows: Update to version 2.1.5-146. http://h18007.www1.hp.com/support/files/server/us/download/23883.html ORIGINAL ADVISORY: HPSBMA02159 SSRT061238: http://itrc.hp.com/service/cki/docDisplay.do?docId=c00786522 OTHER REFERENCES: SA17371: http://secunia.com/advisories/17371/ ---------------------------------------------------------------------- About: This Advisory was delivered by Secunia as a free service to help everybody keeping their systems up to date against the latest vulnerabilities. Subscribe: http://secunia.com/secunia_security_advisories/ Definitions: (Criticality, Where etc.) http://secunia.com/about_secunia_advisories/ Please Note: Secunia recommends that you verify all advisories you receive by clicking the link. Secunia NEVER sends attached files with advisories. Secunia does not advise people to install third party patches, only use those supplied by the vendor. ---------------------------------------------------------------------- Unsubscribe: Secunia Security Advisories http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org ----------------------------------------------------------------------