HP Systems Insight Manager Unspecified Directory Traversal Vulnerability
BID:16571
Info
HP Systems Insight Manager Unspecified Directory Traversal Vulnerability
| Bugtraq ID: | 16571 |
| Class: | Input Validation Error |
| CVE: |
CVE-2006-0656 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 09 2006 12:00AM |
| Updated: | Jun 27 2007 08:08PM |
| Credit: | This issue was disclosed by the vendor. |
| Vulnerable: |
HP Systems Insight Manager 5.0 SP3 HP Systems Insight Manager 5.0 SP2 HP Systems Insight Manager 5.0 SP1 HP Systems Insight Manager 5.0 HP Systems Insight Manager 4.2 SP2 HP Systems Insight Manager 4.2 SP1 HP Systems Insight Manager 4.2 |
| Not Vulnerable: | |
Discussion
HP Systems Insight Manager Unspecified Directory Traversal Vulnerability
HP Systems Insight Manager (SIM) is prone to an unspecified directory-traversal vulnerability. This issue is most likely due to a failure in the application to properly sanitize user-supplied input.
Presumably, an attacker can exploit this issue to retrieve arbitrary files in the context of the affected application. This issue may also permit the overwriting of arbitrary files.
The exact nature of this vulnerability is not currently known; this BID will be updated as further information becomes available.
This issue affects only HP SIM on Microsoft Windows 2000, 2003, and XP.
HP Systems Insight Manager (SIM) is prone to an unspecified directory-traversal vulnerability. This issue is most likely due to a failure in the application to properly sanitize user-supplied input.
Presumably, an attacker can exploit this issue to retrieve arbitrary files in the context of the affected application. This issue may also permit the overwriting of arbitrary files.
The exact nature of this vulnerability is not currently known; this BID will be updated as further information becomes available.
This issue affects only HP SIM on Microsoft Windows 2000, 2003, and XP.
Exploit / POC
HP Systems Insight Manager Unspecified Directory Traversal Vulnerability
An exploit is most likely not required.
An exploit is most likely not required.
Solution / Fix
HP Systems Insight Manager Unspecified Directory Traversal Vulnerability
Solution:
The vendor has released an update addressing this issue. Please see the referenced advisory for further information.
Solution:
The vendor has released an update addressing this issue. Please see the referenced advisory for further information.
References
HP Systems Insight Manager Unspecified Directory Traversal Vulnerability
References:
References: