vendor:
HP Data Protector
by:
@fdiskyou
7.5
CVSS
HIGH
Remote Code Execution
94
CWE
Product Name: HP Data Protector
Affected Version From: 6.11
Affected Version To: 6.11
Patch Exists: YES
Related CWE: CVE-2011-0922
CPE: a:hp:data_protector:6.11
Platforms Tested: Windows 2003 Server SP2
2011
HP Data Protector Cliet EXEC_SETUP Remote Code Execution Vulnerability PoC (ZDI-11-056)
The following PoC instructs an HP Data Protector Client to download and install an .exe file. It tries to get the file from a share (pwn2003se.home.it) and if it fails it tries to access the same file via HTTP. To get the PoC working with this payload share a malicious file via HTTP under http://pwn2003se.home.it/Omniback/i386/installservice.exe.exe and you are done. Tweak payload to better suit your needs.
Mitigation:
Apply the official patch provided by HP.