HP Power Manager 'formExportDataLogs' Directory Traversal Remote Code Execution Vulnerability
BID:37873
Info
HP Power Manager 'formExportDataLogs' Directory Traversal Remote Code Execution Vulnerability
| Bugtraq ID: | 37873 |
| Class: | Input Validation Error |
| CVE: |
CVE-2009-4000 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 19 2010 12:00AM |
| Updated: | Jan 19 2010 12:00AM |
| Credit: | Alin Rad Pop, Secunia Research |
| Vulnerable: |
HP Power Manager 4.2.9 HP Power Manager 4.2.7 HP Power Manager 4.0Build11 HP Power Manager 4.0Build10 HP Power Manager 0 |
| Not Vulnerable: |
HP Power Manager 4.2.10 |
Discussion
HP Power Manager 'formExportDataLogs' Directory Traversal Remote Code Execution Vulnerability
HP Power Manager is prone to a remote code-execution vulnerability because it fails to properly validate user-supplied data.
An attacker can exploit this issue to overwrite arbitrary files and execute arbitrary code with SYSTEM privileges, resulting in a complete compromise of the affected computer.
Versions prior to Power Manager 4.2.10 are affected.
HP Power Manager is prone to a remote code-execution vulnerability because it fails to properly validate user-supplied data.
An attacker can exploit this issue to overwrite arbitrary files and execute arbitrary code with SYSTEM privileges, resulting in a complete compromise of the affected computer.
Versions prior to Power Manager 4.2.10 are affected.
Solution / Fix
HP Power Manager 'formExportDataLogs' Directory Traversal Remote Code Execution Vulnerability
Solution:
The vendor has released updates and an advisory. Please see the references for details.
Solution:
The vendor has released updates and an advisory. Please see the references for details.
References
HP Power Manager 'formExportDataLogs' Directory Traversal Remote Code Execution Vulnerability
References:
References:
- HP Power Manager Homepage (HP)
- Release Notes for HP Power Manager v4.2.10 (Windows Management Server) (HP)
- Secunia Research: HP Power Manager 'formExportDataLogs' Directory Traversal (Secunia Research)
- [security bulletin] HPSBMA02485 SSRT090252 rev.1 - HP Power Manager, Remote Exec ([email protected])