CVE-2009-4000: Path Traversal
Published Jan 20, 2010
·Updated
Directory traversal vulnerability in goform/formExportDataLogs in HP Power Manager before 4.2.10 allows remote attackers to overwrite arbitrary files, and execute arbitrary code, via directory traversal sequences in the fileName parameter.
Affected Software
5 affected components
hp Power Manager<=4.2.9
hp Power Manager=4.2.5
hp Power Manager=4.2.8
hp Power Manager=4.2.6
hp Power Manager=4.2.7
Event History
Jan 20, 2010
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Data Sourced
via NVD·10:30 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2009-4000?
CVE-2009-4000 has a high severity due to its capability to allow remote code execution and arbitrary file overwriting.
2
What versions of HP Power Manager are affected by CVE-2009-4000?
CVE-2009-4000 affects HP Power Manager versions prior to 4.2.10, specifically versions 4.2.5 to 4.2.9.
3
How do I fix CVE-2009-4000?
To fix CVE-2009-4000, upgrade HP Power Manager to version 4.2.10 or later.
4
What type of attack can be carried out using CVE-2009-4000?
CVE-2009-4000 allows attackers to exploit a directory traversal vulnerability to overwrite files and execute arbitrary code.
5
Is authentication required to exploit CVE-2009-4000?
CVE-2009-4000 can be exploited without authentication, making it particularly dangerous.