HP System Management Homepage Unspecified Directory Traversal Vulnerability
BID:16876
Info
HP System Management Homepage Unspecified Directory Traversal Vulnerability
| Bugtraq ID: | 16876 |
| Class: | Input Validation Error |
| CVE: |
CVE-2006-1023 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 28 2006 12:00AM |
| Updated: | Jun 28 2007 03:38AM |
| Credit: | This issue was disclosed by the vendor. |
| Vulnerable: |
HP System Management Homepage 2.1.4 HP System Management Homepage 2.1.3 HP System Management Homepage 2.1.2 HP System Management Homepage 2.1.1 HP System Management Homepage 2.1 HP System Management Homepage 2.0.2 HP System Management Homepage 2.0.1 HP System Management Homepage 2.0 |
| Not Vulnerable: | |
Discussion
HP System Management Homepage Unspecified Directory Traversal Vulnerability
HP System Management Homepage (SMH) is prone to an unspecified directory-traversal vulnerability. This issue is most likely due to a failure in the application to properly sanitize user-supplied input.
Presumably, an attacker can exploit this issue to retrieve arbitrary files in the context of the affected application. This issue may also permit the overwriting of arbitrary files.
The exact nature of this vulnerability is not currently known; this BID will be updated as further information becomes available.
This issue affects HP SMH only on the Microsoft Windows platform.
This issue is likely similar to the one described in BID 16571 (HP Systems Insight Manager Unspecified Directory Traversal Vulnerability), possibly due to code reuse among products.
HP System Management Homepage (SMH) is prone to an unspecified directory-traversal vulnerability. This issue is most likely due to a failure in the application to properly sanitize user-supplied input.
Presumably, an attacker can exploit this issue to retrieve arbitrary files in the context of the affected application. This issue may also permit the overwriting of arbitrary files.
The exact nature of this vulnerability is not currently known; this BID will be updated as further information becomes available.
This issue affects HP SMH only on the Microsoft Windows platform.
This issue is likely similar to the one described in BID 16571 (HP Systems Insight Manager Unspecified Directory Traversal Vulnerability), possibly due to code reuse among products.
Exploit / POC
HP System Management Homepage Unspecified Directory Traversal Vulnerability
An exploit is most likely not required.
An exploit is most likely not required.
Solution / Fix
HP System Management Homepage Unspecified Directory Traversal Vulnerability
Solution:
The vendor has released an advisory to address this issue. No fixes have been released, but the recommended workarounds reportedly resolve this issue. Please see the referenced advisory for further information.
Solution:
The vendor has released an advisory to address this issue. No fixes have been released, but the recommended workarounds reportedly resolve this issue. Please see the referenced advisory for further information.
References
HP System Management Homepage Unspecified Directory Traversal Vulnerability
References:
References: