Back to search
CVE-2011-0923
Published: Feb 9, 2011
Modified: Aug 6, 2024
PUBLISHED
Description
The client in HP Data Protector does not properly validate EXEC_CMD arguments, which allows remote attackers to execute arbitrary Perl code via a crafted command, related to the "local bin directory."
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
http://dvlabs.tippingpoint.com/blog/2011/02/07/zdi-disclosure-hp
x_refsource_MISC
SSRT100441
vendor-advisory
x_refsource_HP
8261
third-party-advisory
x_refsource_SREASON
ADV-2011-0308
vdb-entry
x_refsource_VUPEN
HPSBMA02654
vendor-advisory
x_refsource_HP
8323
third-party-advisory
x_refsource_SREASON
http://zerodayinitiative.com/advisories/ZDI-11-055/
x_refsource_MISC
8329
third-party-advisory
x_refsource_SREASON
46234
vdb-entry
x_refsource_BID
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now