Unrated severityNVD Advisory· Published Nov 18, 2013· Updated Apr 29, 2026
CVE-2013-4842
CVE-2013-4842
Description
Cross-site scripting (XSS) vulnerability in HP Integrated Lights-Out 4 (iLO4) with firmware before 1.32 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected products
8- cpe:2.3:h:hp:integrated_lights-out_4:-:*:*:*:*:*:*:*
cpe:2.3:o:hp:integrated_lights-out_firmware:*:*:*:*:*:*:*:*+ 6 more
- cpe:2.3:o:hp:integrated_lights-out_firmware:*:*:*:*:*:*:*:*range: <=1.27a
- cpe:2.3:o:hp:integrated_lights-out_firmware:1.10:*:*:*:*:*:*:*
- cpe:2.3:o:hp:integrated_lights-out_firmware:1.15:*:*:*:*:*:*:*
- cpe:2.3:o:hp:integrated_lights-out_firmware:1.15a:*:*:*:*:*:*:*
- cpe:2.3:o:hp:integrated_lights-out_firmware:1.16a:*:*:*:*:*:*:*
- cpe:2.3:o:hp:integrated_lights-out_firmware:1.20a:*:*:*:*:*:*:*
- cpe:2.3:o:hp:integrated_lights-out_firmware:1.26a:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- h20564.www2.hp.com/portal/site/hpsc/public/kb/docDisplaynvdVendor Advisory
News mentions
0No linked articles in our index yet.