CVE-2009-4000
Directory traversal vulnerability in goform/formExportDataLogs in HP Power Manager before 4.2.10 allows remote attackers to overwrite arbitrary files, and execute arbitrary code, via directory traversal sequences in the fileName parameter.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 19.8%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
Directory traversal vulnerability in goform/formExportDataLogs in HP Power Manager before 4.2.10 allows remote attackers to overwrite arbitrary files, and execute arbitrary code, via directory traversal sequences in the fileName parameter.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 19.78% probability · 97th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- hp/power manager
- Source
- PSIRT-CNA@flexerasoftware.com
References
- http://marc.info/?l=bugtraq&m=126393370331959&w=2Vendor Advisory
- http://secunia.com/advisories/37280Vendor Advisory
- http://secunia.com/secunia_research/2009-48/Vendor Advisory
- http://securitytracker.com/id?1023470
- http://www.securityfocus.com/bid/37873
- http://marc.info/?l=bugtraq&m=126393370331959&w=2Vendor Advisory
- http://secunia.com/advisories/37280Vendor Advisory
- http://secunia.com/secunia_research/2009-48/Vendor Advisory
- http://securitytracker.com/id?1023470
- http://www.securityfocus.com/bid/37873
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.