10
CVSSv2

CVE-2009-4188

Published: 03/12/2009 Updated: 04/12/2009
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

HP Operations Dashboard has a default password of j2deployer for the j2deployer account, which allows remote malicious users to execute arbitrary code via a session that uses the manager role to conduct unrestricted file upload attacks against the /manager servlet in the Tomcat servlet container. NOTE: this might overlap CVE-2009-3098.

Vulnerable Product Search on Vulmon Subscribe to Product

hp operations dashboard

Exploits

source: wwwsecurityfocuscom/bid/36258/info HP Operations Dashboard is prone to a remote security vulnerability Operations Dashboard 21 for Windows is vulnerable; other versions may also be vulnerable Attackers can exploit this issue using readily available tools The following authentication credentials are available: j2deployer:j2 ...
## # $Id: tomcat_mgr_deployrb 11330 2010-12-14 17:26:44Z egypt $ ## ## # This file is part of the Metasploit Framework and may be subject to # redistribution and commercial restrictions Please see the Metasploit # Framework web site for more information on licensing and terms of use # metasploitcom/framework/ ## require 'msf/core' cla ...