Lucene search

K
saintSAINT CorporationSAINT:8DC4A670199A534D615433A9469A9871
HistoryJan 09, 2009 - 12:00 a.m.

HP OpenView Network Node Manager Toolbar.exe CGI buffer overflow

2009-01-0900:00:00
SAINT Corporation
download.saintcorporation.com
21

EPSS

0.831

Percentile

98.5%

Added: 01/09/2009
CVE: CVE-2008-0067
BID: 33147

Background

HP OpenView Network Node Manager is network availability and performance management software.

Problem

A buffer overflow vulnerability allows remote attackers to execute arbitrary commands by requesting the **Toolbar.exe** CGI program with a long, specially crafted parameter.

Resolution

Apply a fix when available, or restrict access to the **Toolbar.exe** CGI program.

References

<http://secunia.com/secunia_research/2008-13/&gt;

Limitations

Exploit works on HP OpenView Network Node Manager 7.5 on Windows 2000.

Platforms

Windows