10
CVSSv2

CVE-2009-4178

Published: 10/12/2009 Updated: 10/10/2018
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Heap-based buffer overflow in OvWebHelp.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote malicious users to execute arbitrary code via a long Topic parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

hp openview network node manager 7.51

hp openview network node manager 7.0.1

hp openview network node manager 7.53

Exploits

## # $Id: hp_nnm_ovwebhelprb 10998 2010-11-11 22:43:22Z jduck $ ## ## # This file is part of the Metasploit Framework and may be subject to # redistribution and commercial restrictions Please see the Metasploit # Framework web site for more information on licensing and terms of use # metasploitcom/framework/ ## require 'msf/core' clas ...
#!/usr/bin/python # Exploit title: HP OpenView NNM OvWebHelpexe CGI Topic overflow # Date: 20100330 # Software link: hpcom<hpcom> # Version: 753 # Tested on: Windows 2003 SP2 # CVE: 2009-4178 # Code: ############################################ # Trying 1721629130 # Connected to 1721629130 # Escape character is '^]' # ...