CVE-2018-6492

Persistent Cross-Site Scripting, and non-persistent HTML Injection in HP Network Operations Management Ultimate, version 2017.07, 2017.11, 2018.02 and in Network Automation, version 10.00, 10.10, 10.11, 10.20, 10.30, 10.40, 10.50. This vulnerability could be remotely exploited to allow persistent cross-site scripting, and non-persistent HTML Injection.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:hp:network_operations_management_ultimate:2017.07:*:*:*:*:*:*:*
cpe:2.3:a:hp:network_operations_management_ultimate:2017.11:*:*:*:*:*:*:*
cpe:2.3:a:hp:network_operations_management_ultimate:2018.02:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:hp:network_automation:10.00:*:*:*:*:*:*:*
cpe:2.3:a:hp:network_automation:10.10:*:*:*:*:*:*:*
cpe:2.3:a:hp:network_automation:10.11:*:*:*:*:*:*:*
cpe:2.3:a:hp:network_automation:10.20:*:*:*:*:*:*:*
cpe:2.3:a:hp:network_automation:10.30:*:*:*:*:*:*:*
cpe:2.3:a:hp:network_automation:10.40:*:*:*:*:*:*:*
cpe:2.3:a:hp:network_automation:10.50:*:*:*:*:*:*:*

History

No history.

Information

Published : 2018-05-22 19:29

Updated : 2024-02-04 19:46


NVD link : CVE-2018-6492

Mitre link : CVE-2018-6492

CVE.ORG link : CVE-2018-6492


JSON object : View

Products Affected

hp

  • network_operations_management_ultimate
  • network_automation
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')