CVE-2008-0068
HP OpenView Network Node Manager (OV NNM) 7.x - 'OpenView5.exe?Action' Traversal Arbitrary File Access
Severity Score
5.0
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
3
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Directory traversal vulnerability in OpenView5.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to read arbitrary files via directory traversal sequences in the Action parameter.
Una vulnerabilidad de salto de directorio en el archivo OpenView5.exe en HP OpenView Network Node Manager (OV NNM) versiones 7.01, 7.51 y 7.53, permite a los atacantes remotos leer archivos arbitrarios por medio secuencias de salto de directorio en el parĂ¡metro Action.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2008-01-03 CVE Reserved
- 2008-04-11 First Exploit
- 2008-04-14 CVE Published
- 2024-08-07 CVE Updated
- 2024-08-11 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CAPEC
References (14)
URL | Tag | Source |
---|---|---|
http://secunia.com/advisories/29796 | Third Party Advisory | |
http://secunia.com/secunia_research/2008-4/advisory | X_refsource_misc | |
http://securityreason.com/securityalert/3814 | Third Party Advisory | |
http://www.osvdb.org/44359 | Vdb Entry | |
http://www.securityfocus.com/archive/1/490771 | Mailing List | |
http://www.securityfocus.com/archive/1/490834/100/0/threaded | Mailing List | |
http://www.securitytracker.com/id?1019838 | Vdb Entry | |
http://www.securitytracker.com/id?1019839 | Vdb Entry | |
http://www.vupen.com/english/advisories/2008/1214/references | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/41790 | Vdb Entry |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/31638 | 2008-04-11 | |
http://aluigi.altervista.org/adv/closedviewx-adv.txt | 2024-08-07 | |
http://www.securityfocus.com/bid/28745 | 2024-08-07 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://marc.info/?l=bugtraq&m=121553649611253&w=2 | 2018-10-15 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Hp Search vendor "Hp" | Openview Network Node Manager Search vendor "Hp" for product "Openview Network Node Manager" | 7.51 Search vendor "Hp" for product "Openview Network Node Manager" and version "7.51" | - |
Affected
| ||||||
Hp Search vendor "Hp" | Openview Network Node Manager Search vendor "Hp" for product "Openview Network Node Manager" | 7.53 Search vendor "Hp" for product "Openview Network Node Manager" and version "7.53" | - |
Affected
|