Computer Security
[EN] securityvulns.ru
no-pyccku



CVECVE-2009-3843
StatusCandidate
DescriptionHP Operations Manager 8.10 on Windows contains a "hidden account" in the XML file that specifies Tomcat users, which allows remote attackers to conduct unrestricted file upload attacks, and thereby execute arbitrary code, by using the org.apache.catalina.manager.HTMLManagerServlet class to make requests to manager/html/upload.
SeverityHigh
CVSS score10
CVSS vector(AV:N/AC:L/Au:N/C:C/I:C/A:C)
PhaseAssigned (12.12.2011)
NVD:http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-3843
ReferencesHP : HPSBMA02478
 HP : SSRT090251
 MISC : http://www.zerodayinitiative.com/advisories/ZDI-09...
 OSVDB : 60317
 SECTRACK : 1023222
 SECUNIA : 37444
 XF : operations-manager-unspecified-sec-bypass(54361)
SecurityVulns:HP Operations Manager backdoor account

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru
test server