vendor:
Data Protector
by:
muts & dookie
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Data Protector
Affected Version From: 6.11
Affected Version To: 6.11
Patch Exists: YES
Related CWE: N/A
CPE: a:hewlett_packard:data_protector
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2010
HP Data Protector 6.11 Remote Buffer Overflow
This exploit is for HP Data Protector 6.11. It is a remote buffer overflow exploit which is tested on Windows 2003 R2 with DEP enabled. It uses a bindshell payload to open a port 4444 on the target machine. The payload size is 355 bytes.
Mitigation:
Disable unnecessary services, use a firewall, and apply the latest security patches.