Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:




bugtraq logo Bugtraq mailing list archives

Re: Portcullis Security Advisory 05-014 HP Openview Remote Command Execution Vulnerability
From: "David Litchfield" <davidl () ngssoftware com>
Date: Thu, 25 Aug 2005 19:50:04 +0100

Affected systems:
It has been confirmed that versions 6.41 and 7.5 are vulnerable on Sun
Solaris 8 (Sparc), however it is highly likely that all versions of the
software on all supported operating systems are likely to be vulnerable,
however this has not been confirmed.

Windows is vulnerable too. I reported these flaws to HP in Februrary.

Details:
It was identified that connectedNodes.ovpl script will take input from a

cdpView.ovpl, freeIPaddrs.ovpl and ecscmg.ovpl are vulnerable, too.

Typhon (http://www.ngssoftware.com/typhon.htm) has been checking for these flaws since February.

Cheers,
David Litchfield


  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]