The CGI scripts in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 do not properly validate an unspecified parameter, which allows remote attackers to execute arbitrary commands by using a command string for this parameter's value, related to a "command injection vulnerability."
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2011-01-13 11:00
Updated : 2017-08-16 18:33
NVD link : CVE-2011-0271
Mitre link : CVE-2011-0271
JSON object : View
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Products Affected
hp
- openview_network_node_manager