vendor:
HP Operations Manager
by:
mr_me
7.5
CVSS
HIGH
Remote Unicode Stack Overflow
119
CWE
Product Name: HP Operations Manager
Affected Version From: HP Operations Manager v8.0
Affected Version To: HP Operations Manager v8.16
Patch Exists: YES
Related CWE: CVE-2010-1033
CPE: a:hp:operations_manager:8.16
Platforms Tested: Windows XP SP3 (IE 6 & 7)
2010
HP Operations Manager <= v8.16 - (srcvw4.dll) LoadFile()/SaveFile() Remote Unicode Stack Overflow PoC
This is a proof-of-concept exploit for a remote unicode stack overflow vulnerability in HP Operations Manager version 8.16. The vulnerability exists in the LoadFile() and SaveFile() functions of the srcvw4.dll module. The exploit allows an attacker to overwrite the address of the seh handler and potentially execute arbitrary code.
Mitigation:
Upgrade to a version higher than v8.16 or apply the patch provided by HP. Disable scripting on HP Operations Manager.