vendor:
Data Protector Client
by:
@fdiskyou
7.5
CVSS
HIGH
Remote Code Execution
78
CWE
Product Name: Data Protector Client
Affected Version From: 6.11
Affected Version To: 6.11
Patch Exists: YES
Related CWE: CVE-2011-0923
CPE: o:hp:data_protector_client
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 2003 Server SP2
2011
HP Data Protector Client EXEC_CMD Remote Code Execution Vulnerability PoC (ZDI-11-055)
This exploit takes advantage of a Directory Path Traversal to execute ipconfig.exe on the remote host.
Mitigation:
HP has released a patch to address this vulnerability.