![]() |
Inicial ▼ Bookkeeping
Online ▼ Auditorias ▼
DNS
Administrado ▼
Acerca de DNS
Ordenar/Renovar
Preguntas Frecuentes
AUP
Dynamic DNS Clients
Configurar Dominios Dynamic DNS Update Password Monitoreo
de Redes ▼
Enterprise
Avanzado
Estándarr
Prueba
Preguntas Frecuentes
Resumen de Precio/Funciones
Ordenar
Muestras
Configure/Status Alert Profiles | ||
ID de Prueba: | 1.3.6.1.4.1.25623.1.0.801388 |
Categoría: | Web application abuses |
Título: | HP OpenView Network Node Manager Multiple Code Execution Vulnerabilities |
Resumen: | HP OpenView Network Node Manager is prone to multiple code execution vulnerabilities. |
Descripción: | Summary: HP OpenView Network Node Manager is prone to multiple code execution vulnerabilities. Vulnerability Insight: Multiple flaws exist due to: - A buffer overflow error in 'CGI' executable when processing an overly long parameter value. - A buffer overflow error in the 'ov.dll' library when processing certain arguments supplied via CGI executables. - An error in 'webappmon.exe' CGI application, which fails to adequately validate user-supplied input. Vulnerability Impact: Successful exploitation will allow attacker to execute arbitrary code in the context of an application. Affected Software/OS: HP OpenView Network Node Manager 7.51 and 7.53 Solution: Upgrade to NNM v7.53 and apply the patch from the linked references. CVSS Score: 10.0 CVSS Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C |
Referencia Cruzada: |
Common Vulnerability Exposure (CVE) ID: CVE-2010-2704 BugTraq ID: 41839 http://www.securityfocus.com/bid/41839 Bugtraq: 20100721 VUPEN Security Research - HP OpenView Network Node Manager "nnmrptconfig.exe" Buffer Overflow (CVE-2010-2703) (Google Search) http://www.securityfocus.com/archive/1/512543/100/0/threaded HPdes Security Advisory: HPSBMA02558 http://marc.info/?l=bugtraq&m=127972286628707&w=2 HPdes Security Advisory: SSRT010158 HPdes Security Advisory: SSRT100158 http://marc.info/?l=bugtraq&m=127974889107645&w=2 http://secunia.com/advisories/40697 http://www.attrition.org/pipermail/vim/2010-July/002374.html http://www.vupen.com/english/advisories/2010/1866 Common Vulnerability Exposure (CVE) ID: CVE-2010-2709 BugTraq ID: 42154 http://www.securityfocus.com/bid/42154 http://www.exploit-db.com/exploits/14547 HPdes Security Advisory: HPSBMA02563 http://seclists.org/bugtraq/2010/Aug/21 HPdes Security Advisory: SSRT100165 http://www.coresecurity.com/content/hp-nnm-ovjavalocale-buffer-overflow http://securitytracker.com/id?1024274 http://securityreason.com/securityalert/8150 XForce ISS Database: hp-ovnnm-ovjavalocale-bo(60880) https://exchange.xforce.ibmcloud.com/vulnerabilities/60880 |
Copyright | Copyright (C) 2010 Greenbone AG |
Esta es sólo una de 146377 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa. Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora. |