First published: Wed Jan 20 2010(Updated: )
Directory traversal vulnerability in goform/formExportDataLogs in HP Power Manager before 4.2.10 allows remote attackers to overwrite arbitrary files, and execute arbitrary code, via directory traversal sequences in the fileName parameter.
Credit: PSIRT-CNA@flexerasoftware.com
Affected Software | Affected Version | How to fix |
---|---|---|
HP Power Manager | <=4.2.9 | |
HP Power Manager | =4.2.5 | |
HP Power Manager | =4.2.8 | |
HP Power Manager | =4.2.6 | |
HP Power Manager | =4.2.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-4000 has a high severity due to its capability to allow remote code execution and arbitrary file overwriting.
CVE-2009-4000 affects HP Power Manager versions prior to 4.2.10, specifically versions 4.2.5 to 4.2.9.
To fix CVE-2009-4000, upgrade HP Power Manager to version 4.2.10 or later.
CVE-2009-4000 allows attackers to exploit a directory traversal vulnerability to overwrite files and execute arbitrary code.
CVE-2009-4000 can be exploited without authentication, making it particularly dangerous.