CVE-2010-2654
IBM Bladecenter Management - Multiple Web Application Vulnerabilities
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
4Exploited in Wild
-Decision
Descriptions
Multiple cross-site scripting (XSS) vulnerabilities on the IBM BladeCenter with Advanced Management Module (AMM) firmware build ID BPET48L, and possibly other versions before 4.7 and 5.0, allow remote attackers to inject arbitrary web script or HTML via the (1) INDEX or (2) IPADDR parameter to private/cindefn.php, (3) the domain parameter to private/power_management_policy_options.php, the slot parameter to (4) private/pm_temp.php or (5) private/power_module.php, (6) the WEBINDEX parameter to private/blade_leds.php, or (7) the SLOT parameter to private/ipmi_bladestatus.php.
Múltiples vulnerabilidades de ejecución de secuencias de comandos en sitios cruzados (XSS) en el BladeCenter de IBM con Advanced Management Module (AMM) firmware build ID BPET48L, y posiblemente otras versiones anteriores a v4.7 y v5.0, permiten a atacantes remotos inyectar secuencias de comandos web o HTML a través del parámetro (1) INDEX o (2) IPADDR a private/cindefn.php, (3) el parámetro dominio a private/power_management_policy_options.php, el parámetro slot a (4) private/pm_temp.php o (5) private/power_module.php, (6) el parámetro WEBINDEX a private/blade_leds.php, o (7) el parámetro SLOT a private/ipmi_bladestatus.php.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2010-07-06 First Exploit
- 2010-07-07 CVE Reserved
- 2010-07-07 CVE Published
- 2023-07-24 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (11)
URL | Tag | Source |
---|---|---|
http://osvdb.org/66122 | Vdb Entry | |
http://osvdb.org/66125 | Vdb Entry | |
http://osvdb.org/66126 | Vdb Entry | |
http://osvdb.org/66127 | Vdb Entry | |
http://osvdb.org/66128 | Vdb Entry | |
http://osvdb.org/66129 | Vdb Entry | |
http://osvdb.org/66130 | Vdb Entry |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/14237 | 2010-07-06 | |
http://dsecrg.com/pages/vul/show.php?id=154 | 2024-08-07 | |
http://www.exploit-db.com/exploits/14237 | 2024-08-07 | |
http://www.securityfocus.com/bid/41383 | 2024-08-07 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Ibm Search vendor "Ibm" | Advanced Management Module Search vendor "Ibm" for product "Advanced Management Module" | <= 2.48 Search vendor "Ibm" for product "Advanced Management Module" and version " <= 2.48" | l |
Affected
| in | Ibm Search vendor "Ibm" | Bladecenter Search vendor "Ibm" for product "Bladecenter" | * | - |
Safe
|
Ibm Search vendor "Ibm" | Advanced Management Module Search vendor "Ibm" for product "Advanced Management Module" | <= 3.54 Search vendor "Ibm" for product "Advanced Management Module" and version " <= 3.54" | g |
Affected
| in | Ibm Search vendor "Ibm" | Bladecenter Search vendor "Ibm" for product "Bladecenter" | * | - |
Safe
|
Ibm Search vendor "Ibm" | Advanced Management Module Search vendor "Ibm" for product "Advanced Management Module" | 1.00 Search vendor "Ibm" for product "Advanced Management Module" and version "1.00" | - |
Affected
| in | Ibm Search vendor "Ibm" | Bladecenter Search vendor "Ibm" for product "Bladecenter" | * | - |
Safe
|
Ibm Search vendor "Ibm" | Advanced Management Module Search vendor "Ibm" for product "Advanced Management Module" | 1.01 Search vendor "Ibm" for product "Advanced Management Module" and version "1.01" | - |
Affected
| in | Ibm Search vendor "Ibm" | Bladecenter Search vendor "Ibm" for product "Bladecenter" | * | - |
Safe
|
Ibm Search vendor "Ibm" | Advanced Management Module Search vendor "Ibm" for product "Advanced Management Module" | 1.20 Search vendor "Ibm" for product "Advanced Management Module" and version "1.20" | - |
Affected
| in | Ibm Search vendor "Ibm" | Bladecenter Search vendor "Ibm" for product "Bladecenter" | * | - |
Safe
|
Ibm Search vendor "Ibm" | Advanced Management Module Search vendor "Ibm" for product "Advanced Management Module" | 1.20 Search vendor "Ibm" for product "Advanced Management Module" and version "1.20" | f |
Affected
| in | Ibm Search vendor "Ibm" | Bladecenter Search vendor "Ibm" for product "Bladecenter" | * | - |
Safe
|
Ibm Search vendor "Ibm" | Advanced Management Module Search vendor "Ibm" for product "Advanced Management Module" | 1.25 Search vendor "Ibm" for product "Advanced Management Module" and version "1.25" | - |
Affected
| in | Ibm Search vendor "Ibm" | Bladecenter Search vendor "Ibm" for product "Bladecenter" | * | - |
Safe
|
Ibm Search vendor "Ibm" | Advanced Management Module Search vendor "Ibm" for product "Advanced Management Module" | 1.25 Search vendor "Ibm" for product "Advanced Management Module" and version "1.25" | e |
Affected
| in | Ibm Search vendor "Ibm" | Bladecenter Search vendor "Ibm" for product "Bladecenter" | * | - |
Safe
|
Ibm Search vendor "Ibm" | Advanced Management Module Search vendor "Ibm" for product "Advanced Management Module" | 1.25 Search vendor "Ibm" for product "Advanced Management Module" and version "1.25" | i |
Affected
| in | Ibm Search vendor "Ibm" | Bladecenter Search vendor "Ibm" for product "Bladecenter" | * | - |
Safe
|
Ibm Search vendor "Ibm" | Advanced Management Module Search vendor "Ibm" for product "Advanced Management Module" | 1.26 Search vendor "Ibm" for product "Advanced Management Module" and version "1.26" | b |
Affected
| in | Ibm Search vendor "Ibm" | Bladecenter Search vendor "Ibm" for product "Bladecenter" | * | - |
Safe
|
Ibm Search vendor "Ibm" | Advanced Management Module Search vendor "Ibm" for product "Advanced Management Module" | 1.26 Search vendor "Ibm" for product "Advanced Management Module" and version "1.26" | e |
Affected
| in | Ibm Search vendor "Ibm" | Bladecenter Search vendor "Ibm" for product "Bladecenter" | * | - |
Safe
|
Ibm Search vendor "Ibm" | Advanced Management Module Search vendor "Ibm" for product "Advanced Management Module" | 1.26 Search vendor "Ibm" for product "Advanced Management Module" and version "1.26" | h |
Affected
| in | Ibm Search vendor "Ibm" | Bladecenter Search vendor "Ibm" for product "Bladecenter" | * | - |
Safe
|
Ibm Search vendor "Ibm" | Advanced Management Module Search vendor "Ibm" for product "Advanced Management Module" | 1.26 Search vendor "Ibm" for product "Advanced Management Module" and version "1.26" | i |
Affected
| in | Ibm Search vendor "Ibm" | Bladecenter Search vendor "Ibm" for product "Bladecenter" | * | - |
Safe
|
Ibm Search vendor "Ibm" | Advanced Management Module Search vendor "Ibm" for product "Advanced Management Module" | 1.26 Search vendor "Ibm" for product "Advanced Management Module" and version "1.26" | k |
Affected
| in | Ibm Search vendor "Ibm" | Bladecenter Search vendor "Ibm" for product "Bladecenter" | * | - |
Safe
|
Ibm Search vendor "Ibm" | Advanced Management Module Search vendor "Ibm" for product "Advanced Management Module" | 1.28 Search vendor "Ibm" for product "Advanced Management Module" and version "1.28" | g |
Affected
| in | Ibm Search vendor "Ibm" | Bladecenter Search vendor "Ibm" for product "Bladecenter" | * | - |
Safe
|
Ibm Search vendor "Ibm" | Advanced Management Module Search vendor "Ibm" for product "Advanced Management Module" | 1.32 Search vendor "Ibm" for product "Advanced Management Module" and version "1.32" | d |
Affected
| in | Ibm Search vendor "Ibm" | Bladecenter Search vendor "Ibm" for product "Bladecenter" | * | - |
Safe
|
Ibm Search vendor "Ibm" | Advanced Management Module Search vendor "Ibm" for product "Advanced Management Module" | 1.34 Search vendor "Ibm" for product "Advanced Management Module" and version "1.34" | b |
Affected
| in | Ibm Search vendor "Ibm" | Bladecenter Search vendor "Ibm" for product "Bladecenter" | * | - |
Safe
|
Ibm Search vendor "Ibm" | Advanced Management Module Search vendor "Ibm" for product "Advanced Management Module" | 1.34 Search vendor "Ibm" for product "Advanced Management Module" and version "1.34" | e |
Affected
| in | Ibm Search vendor "Ibm" | Bladecenter Search vendor "Ibm" for product "Bladecenter" | * | - |
Safe
|
Ibm Search vendor "Ibm" | Advanced Management Module Search vendor "Ibm" for product "Advanced Management Module" | 1.36 Search vendor "Ibm" for product "Advanced Management Module" and version "1.36" | d |
Affected
| in | Ibm Search vendor "Ibm" | Bladecenter Search vendor "Ibm" for product "Bladecenter" | * | - |
Safe
|
Ibm Search vendor "Ibm" | Advanced Management Module Search vendor "Ibm" for product "Advanced Management Module" | 1.36 Search vendor "Ibm" for product "Advanced Management Module" and version "1.36" | g |
Affected
| in | Ibm Search vendor "Ibm" | Bladecenter Search vendor "Ibm" for product "Bladecenter" | * | - |
Safe
|
Ibm Search vendor "Ibm" | Advanced Management Module Search vendor "Ibm" for product "Advanced Management Module" | 1.36 Search vendor "Ibm" for product "Advanced Management Module" and version "1.36" | h |
Affected
| in | Ibm Search vendor "Ibm" | Bladecenter Search vendor "Ibm" for product "Bladecenter" | * | - |
Safe
|
Ibm Search vendor "Ibm" | Advanced Management Module Search vendor "Ibm" for product "Advanced Management Module" | 1.36 Search vendor "Ibm" for product "Advanced Management Module" and version "1.36" | k |
Affected
| in | Ibm Search vendor "Ibm" | Bladecenter Search vendor "Ibm" for product "Bladecenter" | * | - |
Safe
|
Ibm Search vendor "Ibm" | Advanced Management Module Search vendor "Ibm" for product "Advanced Management Module" | 1.42 Search vendor "Ibm" for product "Advanced Management Module" and version "1.42" | d |
Affected
| in | Ibm Search vendor "Ibm" | Bladecenter Search vendor "Ibm" for product "Bladecenter" | * | - |
Safe
|
Ibm Search vendor "Ibm" | Advanced Management Module Search vendor "Ibm" for product "Advanced Management Module" | 1.42 Search vendor "Ibm" for product "Advanced Management Module" and version "1.42" | f |
Affected
| in | Ibm Search vendor "Ibm" | Bladecenter Search vendor "Ibm" for product "Bladecenter" | * | - |
Safe
|
Ibm Search vendor "Ibm" | Advanced Management Module Search vendor "Ibm" for product "Advanced Management Module" | 1.42 Search vendor "Ibm" for product "Advanced Management Module" and version "1.42" | i |
Affected
| in | Ibm Search vendor "Ibm" | Bladecenter Search vendor "Ibm" for product "Bladecenter" | * | - |
Safe
|
Ibm Search vendor "Ibm" | Advanced Management Module Search vendor "Ibm" for product "Advanced Management Module" | 1.42 Search vendor "Ibm" for product "Advanced Management Module" and version "1.42" | n |
Affected
| in | Ibm Search vendor "Ibm" | Bladecenter Search vendor "Ibm" for product "Bladecenter" | * | - |
Safe
|
Ibm Search vendor "Ibm" | Advanced Management Module Search vendor "Ibm" for product "Advanced Management Module" | 1.42 Search vendor "Ibm" for product "Advanced Management Module" and version "1.42" | o |
Affected
| in | Ibm Search vendor "Ibm" | Bladecenter Search vendor "Ibm" for product "Bladecenter" | * | - |
Safe
|
Ibm Search vendor "Ibm" | Advanced Management Module Search vendor "Ibm" for product "Advanced Management Module" | 1.42 Search vendor "Ibm" for product "Advanced Management Module" and version "1.42" | t |
Affected
| in | Ibm Search vendor "Ibm" | Bladecenter Search vendor "Ibm" for product "Bladecenter" | * | - |
Safe
|
Ibm Search vendor "Ibm" | Advanced Management Module Search vendor "Ibm" for product "Advanced Management Module" | 2.46 Search vendor "Ibm" for product "Advanced Management Module" and version "2.46" | c |
Affected
| in | Ibm Search vendor "Ibm" | Bladecenter Search vendor "Ibm" for product "Bladecenter" | * | - |
Safe
|
Ibm Search vendor "Ibm" | Advanced Management Module Search vendor "Ibm" for product "Advanced Management Module" | 2.46 Search vendor "Ibm" for product "Advanced Management Module" and version "2.46" | j |
Affected
| in | Ibm Search vendor "Ibm" | Bladecenter Search vendor "Ibm" for product "Bladecenter" | * | - |
Safe
|
Ibm Search vendor "Ibm" | Advanced Management Module Search vendor "Ibm" for product "Advanced Management Module" | 2.48 Search vendor "Ibm" for product "Advanced Management Module" and version "2.48" | c |
Affected
| in | Ibm Search vendor "Ibm" | Bladecenter Search vendor "Ibm" for product "Bladecenter" | * | - |
Safe
|
Ibm Search vendor "Ibm" | Advanced Management Module Search vendor "Ibm" for product "Advanced Management Module" | 2.48 Search vendor "Ibm" for product "Advanced Management Module" and version "2.48" | d |
Affected
| in | Ibm Search vendor "Ibm" | Bladecenter Search vendor "Ibm" for product "Bladecenter" | * | - |
Safe
|
Ibm Search vendor "Ibm" | Advanced Management Module Search vendor "Ibm" for product "Advanced Management Module" | 2.48 Search vendor "Ibm" for product "Advanced Management Module" and version "2.48" | g |
Affected
| in | Ibm Search vendor "Ibm" | Bladecenter Search vendor "Ibm" for product "Bladecenter" | * | - |
Safe
|
Ibm Search vendor "Ibm" | Advanced Management Module Search vendor "Ibm" for product "Advanced Management Module" | 2.48 Search vendor "Ibm" for product "Advanced Management Module" and version "2.48" | n |
Affected
| in | Ibm Search vendor "Ibm" | Bladecenter Search vendor "Ibm" for product "Bladecenter" | * | - |
Safe
|
Ibm Search vendor "Ibm" | Advanced Management Module Search vendor "Ibm" for product "Advanced Management Module" | 2.50 Search vendor "Ibm" for product "Advanced Management Module" and version "2.50" | c |
Affected
| in | Ibm Search vendor "Ibm" | Bladecenter Search vendor "Ibm" for product "Bladecenter" | * | - |
Safe
|
Ibm Search vendor "Ibm" | Advanced Management Module Search vendor "Ibm" for product "Advanced Management Module" | 2.50 Search vendor "Ibm" for product "Advanced Management Module" and version "2.50" | g |
Affected
| in | Ibm Search vendor "Ibm" | Bladecenter Search vendor "Ibm" for product "Bladecenter" | * | - |
Safe
|
Ibm Search vendor "Ibm" | Advanced Management Module Search vendor "Ibm" for product "Advanced Management Module" | 2.50 Search vendor "Ibm" for product "Advanced Management Module" and version "2.50" | k |
Affected
| in | Ibm Search vendor "Ibm" | Bladecenter Search vendor "Ibm" for product "Bladecenter" | * | - |
Safe
|
Ibm Search vendor "Ibm" | Advanced Management Module Search vendor "Ibm" for product "Advanced Management Module" | 2.50 Search vendor "Ibm" for product "Advanced Management Module" and version "2.50" | p |
Affected
| in | Ibm Search vendor "Ibm" | Bladecenter Search vendor "Ibm" for product "Bladecenter" | * | - |
Safe
|
Ibm Search vendor "Ibm" | Advanced Management Module Search vendor "Ibm" for product "Advanced Management Module" | 3.54 Search vendor "Ibm" for product "Advanced Management Module" and version "3.54" | d |
Affected
| in | Ibm Search vendor "Ibm" | Bladecenter Search vendor "Ibm" for product "Bladecenter" | * | - |
Safe
|