HP Data Protector 'EXEC_INTEGUTIL' Messages Remote Command Execution Vulnerability
BID:70244
Info
HP Data Protector 'EXEC_INTEGUTIL' Messages Remote Command Execution Vulnerability
| Bugtraq ID: | 70244 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 02 2014 12:00AM |
| Updated: | Oct 02 2014 12:00AM |
| Credit: | [email protected] |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
HP Data Protector 'EXEC_INTEGUTIL' Messages Remote Command Execution Vulnerability
HP Data Protector is prone to a remote command-execution vulnerability because it fails to adequately sanitize user-supplied input.
A remote attacker can leverage this issue to execute arbitrary commands in the context of the SYSTEM user. Failed exploit attempts will likely result in denial-of-service conditions.
HP Data Protector is prone to a remote command-execution vulnerability because it fails to adequately sanitize user-supplied input.
A remote attacker can leverage this issue to execute arbitrary commands in the context of the SYSTEM user. Failed exploit attempts will likely result in denial-of-service conditions.
Exploit / POC
HP Data Protector 'EXEC_INTEGUTIL' Messages Remote Command Execution Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
HP Data Protector 'EXEC_INTEGUTIL' Messages Remote Command Execution Vulnerability
References:
References: