CVE-2011-1865
60Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 89%
from disclosure to weapon0 days
Published on NVDJul 1
1st PoCJun 29
metasploitJun 29
exploitation probability
89%top 1% of all CVEs
observed exploitation
nono source reports it
8 public exploit(s)
Multiple stack-based buffer overflows in the inet service in HP OpenView Storage Data Protector 6.00 through 6.20 allow remote attackers to execute arbitrary code via a request containing crafted parameters.
Affected products
n/a · n/apublic PoCs found — 8✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/17490exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/17458exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/17467exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/17468cve_referencewww.exploit-db.com/exploits/17458unverifiedcve_referencewww.exploit-db.com/exploits/17467unverifiedcve_referencewww.exploit-db.com/exploits/17468unverifiedcve_referencewww.exploit-db.com/exploits/17490unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c02872182http://secunia.com/advisories/45100http://securityreason.com/securityalert/8288http://securityreason.com/securityalert/8290http://securityreason.com/securityalert/8291http://securityreason.com/securityalert/8295http://securitytracker.com/id?1025731https://exchange.xforce.ibmcloud.com/vulnerabilities/68281http://www.coresecurity.com/content/HP-Data-Protector-multiple-vulnerabilitieshttp://www.exploit-db.com/exploits/17458http://www.exploit-db.com/exploits/17467http://www.exploit-db.com/exploits/17468