HP System Management Homepage CVE-2013-3576 Command Injection Vulnerability
BID:60471
Info
HP System Management Homepage CVE-2013-3576 Command Injection Vulnerability
| Bugtraq ID: | 60471 |
| Class: | Input Validation Error |
| CVE: |
CVE-2013-3576 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 11 2013 12:00AM |
| Updated: | Sep 21 2013 12:11AM |
| Credit: | Markus Wulftange from Daimler TSS |
| Vulnerable: |
HP System Management Homepage 6.2.2 7 HP System Management Homepage 2.2.8 HP System Management Homepage 2.2.6 HP System Management Homepage 2.1.12 HP System Management Homepage 2.1.11 HP System Management Homepage 2.1.10 HP System Management Homepage 2.1.9 HP System Management Homepage 2.1.8 HP System Management Homepage 2.1.7 HP System Management Homepage 2.1.6 HP System Management Homepage 2.1.5 HP System Management Homepage 2.1.4 HP System Management Homepage 2.1.3 HP System Management Homepage 2.1.2 HP System Management Homepage 2.1.1 HP System Management Homepage 2.1 HP System Management Homepage 2.0.2 HP System Management Homepage 2.0.1 HP System Management Homepage 2.0 HP System Management Homepage 7.0 HP System Management Homepage 6.3 HP System Management Homepage 6.2 HP System Management Homepage 6.1 HP System Management Homepage 6.0 |
| Not Vulnerable: | |
Discussion
HP System Management Homepage CVE-2013-3576 Command Injection Vulnerability
HP System Management Homepage is prone to a remote command-injection vulnerability because it fails to properly sanitize user-supplied input.
Successfully exploiting this issue may allow an attacker to execute arbitrary commands in context of the affected application.
HP System Management Homepage is prone to a remote command-injection vulnerability because it fails to properly sanitize user-supplied input.
Successfully exploiting this issue may allow an attacker to execute arbitrary commands in context of the affected application.
Exploit / POC
HP System Management Homepage CVE-2013-3576 Command Injection Vulnerability
An attacker can exploit this issue using a web browser.
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product.
The following exploit and example URI are available:
https://www.example.com/smhutil/snmpchp/&&whoami&&echo
An attacker can exploit this issue using a web browser.
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product.
The following exploit and example URI are available:
https://www.example.com/smhutil/snmpchp/&&whoami&&echo
Solution / Fix
HP System Management Homepage CVE-2013-3576 Command Injection Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
HP System Management Homepage CVE-2013-3576 Command Injection Vulnerability
References:
References: