Get a Pentest and security assessment of your IT network.

Advisories

Digital Defense VRT Advisory 2008.19

The HP-ChaiSOE/1.0 embedded web server on certain HP JetDirect printers allows a potential attacker to gain read only access to directories and files outside of the web root. An attacker can leverage this flaw to read arbitrary system configuration files, cached documents, etc. Information obtained from an affected host may facilitate further attacks against the host. Exploitation of this flaw is trivial using common web server directory traversal techniques. Verified vulnerable systems include the HP JetDirect 2420 and the HP JetDirect 4250.

 

You can download this advisory from the following link: https://packetstormsecurity.com/files/download/74640/DDIVRT-2008-19.txt

Source: https://packetstormsecurity.com/files/74640/Digital-Defense-VRT-Advisory-2008.19.html

Related posts
Advisories

Secunia Security Advisory 15017

Advisories

Secunia Security Advisory 18394

Advisories

Secunia Security Advisory 21136

Advisories

Secunia Security Advisory 24114