VYPR
Unrated severityNVD Advisory· Published Oct 13, 2008· Updated Apr 23, 2026

CVE-2008-4411

CVE-2008-4411

Description

Cross-site scripting (XSS) vulnerability in HP System Management Homepage (SMH) before 2.1.15.210 on Linux and Windows allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2008-1663.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Cross-site scripting vulnerability in HP System Management Homepage (SMH) before 2.1.15.210 allows remote attackers to inject arbitrary web script or HTML.

Vulnerability

A cross-site scripting (XSS) vulnerability exists in HP System Management Homepage (SMH) versions prior to 2.1.15.210 on Linux and Windows. The vulnerability arises from unspecified vectors that allow injection of arbitrary web script or HTML. This issue is distinct from CVE-2008-1663 [1].

Exploitation

An unauthenticated remote attacker can exploit this vulnerability by sending a crafted request to the SMH web interface. No user interaction or special network position is required beyond network access to the SMH service [1].

Impact

Successful exploitation enables the attacker to execute arbitrary script or HTML in the context of the victim's browser session. This can lead to session hijacking, credential theft, or other actions performed on behalf of the authenticated user [1].

Mitigation

HP has released SMH version 2.1.15.210 to address this vulnerability. Users should upgrade to this version or later, available from the HP support website. No workarounds are documented [1].

AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

32
  • cpe:2.3:a:hp:system_management_homepage:*:*:*:*:*:*:*:*+ 31 more
    • cpe:2.3:a:hp:system_management_homepage:*:*:*:*:*:*:*:*range: <=2.1.12-200
    • cpe:2.3:a:hp:system_management_homepage:2.0.0:*:*:*:*:*:*:*
    • cpe:2.3:a:hp:system_management_homepage:2.0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:hp:system_management_homepage:2.0.2:*:*:*:*:*:*:*
    • cpe:2.3:a:hp:system_management_homepage:2.1:*:*:*:*:*:*:*
    • cpe:2.3:a:hp:system_management_homepage:2.1.0-103:*:*:*:*:*:*:*
    • cpe:2.3:a:hp:system_management_homepage:2.1.0-103\(a\):*:*:*:*:*:*:*
    • cpe:2.3:a:hp:system_management_homepage:2.1.0-109:*:*:*:*:*:*:*
    • cpe:2.3:a:hp:system_management_homepage:2.1.0-118:*:*:*:*:*:*:*
    • cpe:2.3:a:hp:system_management_homepage:2.1.1:*:*:*:*:*:*:*
    • cpe:2.3:a:hp:system_management_homepage:2.1.10:*:*:*:*:*:*:*
    • cpe:2.3:a:hp:system_management_homepage:2.1.10-186:*:*:*:*:*:*:*
    • cpe:2.3:a:hp:system_management_homepage:2.1.11:*:*:*:*:*:*:*
    • cpe:2.3:a:hp:system_management_homepage:2.1.11-197:*:*:*:*:*:*:*
    • cpe:2.3:a:hp:system_management_homepage:2.1.12-118:*:*:*:*:*:*:*
    • cpe:2.3:a:hp:system_management_homepage:2.1.2:*:*:*:*:*:*:*
    • cpe:2.3:a:hp:system_management_homepage:2.1.2-127:*:*:*:*:*:*:*
    • cpe:2.3:a:hp:system_management_homepage:2.1.3:*:*:*:*:*:*:*
    • cpe:2.3:a:hp:system_management_homepage:2.1.3.132:*:*:*:*:*:*:*
    • cpe:2.3:a:hp:system_management_homepage:2.1.4:*:*:*:*:*:*:*
    • cpe:2.3:a:hp:system_management_homepage:2.1.4-143:*:*:*:*:*:*:*
    • cpe:2.3:a:hp:system_management_homepage:2.1.5:*:*:*:*:*:*:*
    • cpe:2.3:a:hp:system_management_homepage:2.1.5-146:*:*:*:*:*:*:*
    • cpe:2.3:a:hp:system_management_homepage:2.1.6:*:*:*:*:*:*:*
    • cpe:2.3:a:hp:system_management_homepage:2.1.6-156:*:*:*:*:*:*:*
    • cpe:2.3:a:hp:system_management_homepage:2.1.7:*:*:*:*:*:*:*
    • cpe:2.3:a:hp:system_management_homepage:2.1.7-168:*:*:*:*:*:*:*
    • cpe:2.3:a:hp:system_management_homepage:2.1.8:*:*:*:*:*:*:*
    • cpe:2.3:a:hp:system_management_homepage:2.1.8-177:*:*:*:*:*:*:*
    • cpe:2.3:a:hp:system_management_homepage:2.1.9:*:*:*:*:*:*:*
    • cpe:2.3:a:hp:system_management_homepage:2.1.9-178:*:*:*:*:*:*:*
    • (no CPE)range: < 2.1.15.210

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

7

News mentions

0

No linked articles in our index yet.