CVE-2011-0923: Input Validation
The client in HP Data Protector does not properly validate EXECCMD arguments, which allows remote attackers to execute arbitrary Perl code via a crafted command, related to the "local bin directory."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-0923?
CVE-2011-0923 is classified as a critical vulnerability due to its potential for arbitrary code execution.
How can I mitigate CVE-2011-0923?
To mitigate CVE-2011-0923, ensure that you are using the latest version of HP Data Protector where this vulnerability is addressed.
What type of attack does CVE-2011-0923 enable?
CVE-2011-0923 enables remote attackers to execute arbitrary Perl code by exploiting improperly validated EXEC_CMD arguments.
What software does CVE-2011-0923 affect?
CVE-2011-0923 specifically affects HP Data Protector regardless of its version.
Is authentication required to exploit CVE-2011-0923?
No authentication is required to exploit CVE-2011-0923, making it particularly dangerous for vulnerable installations.