vendor:
OpenView Network Node Manager
by:
Shahin
N/A
CVSS
N/A
Remote Code Execution
119
CWE
Product Name: OpenView Network Node Manager
Affected Version From: 7.53
Affected Version To: 7.53
Patch Exists: YES
Related CWE: CVE-2010-2703
CPE: a:hp:openview_network_node_manager:7.53
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2010
HP OpenView NNM webappmon.exe execvp_nc Remote Code Execution
A buffer overflow vulnerability exists in HP OpenView Network Node Manager 7.53. An attacker can send a specially crafted HTTP POST request to the webappmon.exe CGI program to execute arbitrary code with SYSTEM privileges.
Mitigation:
Upgrade to the latest version of HP OpenView Network Node Manager.