Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2009-0940

EPSS 0.84% · P75
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2009-0940

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Multiple cross-site request forgery (CSRF) vulnerabilities in the HP Embedded Web Server (EWS) on HP LaserJet Printers, Edgeline Printers, and Digital Senders allow remote attackers to hijack the intranet connectivity of arbitrary users for requests that (1) print documents via unknown vectors, (2) modify the network configuration via a NetIPChange request to hp/device/config_result_YesNo.html/config, or (3) change the password via the Password and ConfirmPassword parameters to hp/device/set_config_password.html/config.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
HP LaserJet打印机HP Embedded Web Server多个跨站请求伪造漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
HP LaserJet是HP推出的激光打印机系列。 LaserJet系列激光打印机所内嵌的WEB服务器默认下接受TCP 9100端口上所发送的打印请求。如果用户受骗访问了包含有恶意代码的网站的话,就可能导致跨站请求伪造攻击,非授权更改打印机网络配置或用户口令。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2009-0940

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2009-0940

登录查看更多情报信息。

Same Patch Batch · n/a · 2009-03-18 · 19 CVEs total

CVE-2009-0538Symantec pcAnywhere本地格式串漏洞
CVE-2009-0939Tor 不完整IPv4地址未明向量拒绝服务漏洞
CVE-2009-0938Tor '畸形输入'拒绝服务漏洞
CVE-2009-0937Tor 目录镜像未知向量拒绝服务漏洞
CVE-2009-0936Tor 未明拒绝服务漏洞
CVE-2009-0935Linux Kernel inotify_read()函数本地拒绝服务漏洞
CVE-2009-0934Process-One ejabberd MUC日志跨站脚本攻击漏洞
CVE-2007-5543Miranda IM多个远程栈溢出漏洞
CVE-2007-5542Miranda IM多个远程栈溢出漏洞
CVE-2009-0941HP LaserJet打印机HP Embedded Web Server 身份验证和权限管理漏洞
CVE-2008-6488SoftComplex PHP Image Gallery 'index.php'SQL注入漏洞
CVE-2008-6487Digiappz DigiAffiliate 脚本login.asp SQL注入漏洞
CVE-2008-6486Shatm Sharedlog CMS 'slideshow_uploadvideo.content.php' PHP远程文件包含漏洞
CVE-2008-6485SoftComplex PHP Image Gallery index.php'ctg参数SQL注入漏洞
CVE-2008-6484Mole Group Taxi Dist-Calc脚本'login.php' SQL注入漏洞
CVE-2008-6483Virtuemart-Solutions Joomla! com_googlebas程序admin.googlebase.php远程文件包含漏洞
CVE-2008-6482Justjoomla Joomla! Flash Tree Gallery组件‘admin.treeg.php’远程文件包含漏洞
CVE-2008-4564Autonomy KeyView模块Word Perfect文件解析栈溢出漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2009-0940

No comments yet


Leave a comment