vendor:
HP OpenView NNM
by:
S2 Crew [Hungary]
7.5
CVSS
HIGH
Remote Code Execution
20
CWE
Product Name: HP OpenView NNM
Affected Version From: 7.53
Affected Version To: 7.53
Patch Exists: NO
Related CWE: CVE-2010-1555
CPE: a:hp:openview_nnm:7.53
Platforms Tested: Windows 2003
2010
HP OpenView NNM getnnmdata.exe CGI Invalid Hostname Remote Code Execution
The exploit allows an attacker to execute arbitrary code on a vulnerable system by sending a specially crafted request to the getnnmdata.exe CGI script. This vulnerability is due to an invalid hostname check in the script, which can be bypassed to execute arbitrary code. The vulnerability has been assigned CVE-2010-1555.
Mitigation:
Apply the vendor-supplied patch or upgrade to a non-vulnerable version.