vendor:
NNM
by:
Nahuel Riva, sinn3r
N/A
CVSS
N/A
Stack-based overflow
119
CWE
Product Name: NNM
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: NO
Related CWE: CVE-2010-2709
CPE: Unknown
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows Server 2003 Enterprise
2011
HP NNM CGI webappmon.exe OvJavaLocale Buffer Overflow
This module exploits a stack-based overflow in HP NNM's webappmon.exe. The vulnerability occurs when a long string of data is sent as OvJavaLocale's cookie value, OvWww.dll fails to properly do any bounds checking before this input is parsed in function OvWwwDebug(), which causes an overflow when sprintf_new() is called.
Mitigation:
No mitigation or remediation available