vendor:
HP OpenView Network Node Manager
by:
S2 Crew
9.3
CVSS
CRITICAL
Remote Code Execution
20
CWE
Product Name: HP OpenView Network Node Manager
Affected Version From: 7.53
Affected Version To: 7.53
Patch Exists: NO
Related CWE: CVE-2010-1554
CPE: a:hp:openview_network_node_manager:7.53
Platforms Tested: Windows 2003
2010
HP OpenView NNM getnnmdata.exe CGI Invalid ICount Remote Code Execution
This exploit allows remote attackers to execute arbitrary code via a crafted ICount parameter in a CGI request to getnnmdata.exe. The vulnerability exists in HP OpenView Network Node Manager (NNM) and allows an attacker to execute arbitrary code with the same privileges as the NNM server.
Mitigation:
Apply the appropriate patch or update provided by the vendor.