vendor:
HP OpenView Network Node Manager
by:
Unknown
9
CVSS
CRITICAL
Buffer Overflow
119
CWE
Product Name: HP OpenView Network Node Manager
Affected Version From: 7.53
Affected Version To: 7.53
Patch Exists: YES
Related CWE: CVE-2009-4178
CPE: a:hp:openview_network_node_manager:7.53
Platforms Tested: Windows 2003 SP2
2010
HP OpenView NNM OvWebHelp.exe CGI Topic overflow
This exploit takes advantage of a buffer overflow vulnerability in HP OpenView NNM's OvWebHelp.exe CGI script. By sending a specially crafted request, an attacker can overflow a buffer and execute arbitrary code on the target system.
Mitigation:
Apply the appropriate patch provided by HP to fix the buffer overflow vulnerability. Additionally, restrict access to the OvWebHelp.exe CGI script to trusted users only.