Lucene search

K
zdiAniway ([email protected])ZDI-12-003
HistoryJan 05, 2012 - 12:00 a.m.

HP OpenView NNM webappmon.exe parameter Remote Code Execution Vulnerability

2012-01-0500:00:00
www.zerodayinitiative.com
13

0.582 Medium

EPSS

Percentile

97.7%

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of OpenView Network Node Manager. Authentication is not required to exploit this vulnerability. The specific flaw exists within webappmon.exe CGI program. When processing crafted parameters, there exists an insufficient boundary check before supplying a format string with the values, causing a stack overflow. This can lead to memory corruption which can be leveraged to execute arbitrary code under the context of the target service.

0.582 Medium

EPSS

Percentile

97.7%