CVE-2011-0271
iDEFENSE Security Advisory 2011-01-10.1
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The CGI scripts in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 do not properly validate an unspecified parameter, which allows remote attackers to execute arbitrary commands by using a command string for this parameter's value, related to a "command injection vulnerability."
Los scripts CGI en HP OpenView Network Node Manager (OV NNM) v7.51 y v7.53 no validan correctamente un parámetro no especificado, el cual permite a atacantes remotos ejecutar código arbitrario mediante un comando string para el valor de este parámetro, relacionado con "vulnerabilidad de inyección de comando"
Remote exploitation of a command injection vulnerability in Hewlett-Packard Development Co. LP (HP)'s Network Node Manager could allow an attacker to execute arbitrary commands with the privileges of the affected service. The vulnerability exists within CGI scripts provided with the NNM HTTP Server. These scripts do not effectively sanitize a particular parameter. It is possible for an attacker to supply a parameter containing a specially crafted command line string. The command line string will be executed on the affected NNM HTTP Server.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2010-12-23 CVE Reserved
- 2011-01-12 CVE Published
- 2024-08-06 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=887 | Third Party Advisory | |
http://www.securityfocus.com/bid/45762 | Vdb Entry | |
http://www.securitytracker.com/id?1024951 | Vdb Entry | |
http://www.vupen.com/english/advisories/2011/0085 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/64657 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.securityfocus.com/archive/1/515628 | 2017-08-17 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Hp Search vendor "Hp" | Openview Network Node Manager Search vendor "Hp" for product "Openview Network Node Manager" | 7.51 Search vendor "Hp" for product "Openview Network Node Manager" and version "7.51" | - |
Affected
| ||||||
Hp Search vendor "Hp" | Openview Network Node Manager Search vendor "Hp" for product "Openview Network Node Manager" | 7.53 Search vendor "Hp" for product "Openview Network Node Manager" and version "7.53" | - |
Affected
|