HP Multiple LaserJet Printers Unspecified Directory Traversal Vulnerability

Multiple HP printers are prone to an unspecified directory-traversal vulnerability because the device's webserver fails to sufficiently sanitize user-supplied input.

Exploiting this issue will allow an attacker to view arbitrary local files within the context of the webserver. Information harvested may aid in launching further attacks.

The following HP printer models are vulnerable:

HP LaserJet 2410 with firmware prior to 20080819 SPCL112A
HP LaserJet 2420 with firmware prior to 20080819 SPCL112A
HP LaserJet 2430 with firmware prior to 20080819 SPCL112A
HP LaserJet P3005 with firmware prior to 02.043.1
HP LaserJet P3015 with firmware prior to 06.043.2
HP LaserJet P4015 with firmware prior to 04.049.0
HP Color LaserJet CP4025 with firmware prior to 07.20.7
HP Color LaserJet CP4525 with firmware prior to 07.20.7
HP LaserJet 4250 with firmware prior to 08.160.4
HP LaserJet 4350 with firmware prior to 08.160.4
HP LaserJet 5200 with firmware prior to 08.062.0
HP Color LaserJet 5550 with firmware prior to 7.014.0
HP LaserJet 9040 with firmware prior to 08.112.0
HP LaserJet 9050 with firmware prior to 08.112.0
HP LaserJet 4345mfp with firmware prior to 09.120.9
HP Color LaserJet 4730mfp with firmware prior to 46.200.9
HP LaserJet 9040mfp with firmware prior to 08.110.9
HP LaserJet 9050mfp with firmware prior to 08.110.9
HP 9200C Digital Sender with firmware prior to 09.120.9
HP 9250 Digital Sender with firmware prior to 48.091.3
HP Color LaserJet 9500mfp with firmware prior to 08.110.9


 

Privacy Statement
Copyright 2010, SecurityFocus