HP-UX PHSS_36385 : HP OpenView Network Node Manager (OV NNM) Running Apache, Remote Cross Site Scripting (XSS), Denial of Service (DoS), Execute Arbitrary Code (HPSBMA02328 SSRT071293 rev.2)

high Nessus Plugin ID 26154

Synopsis

The remote HP-UX host is missing a security-related patch.

Description

s700_800 11.X PA-RISC OV NNM7.51 Intermediate Patch 16 :

Potential vulnerabilities have been identified with HP OpenView Network Node Manager (OV NNM) running Apache. These vulnerabilities could be exploited remotely resulting in cross site scripting (XSS), Denial of Service (DoS), or execution of arbitrary code.

Solution

Install patch PHSS_36385 or subsequent.

See Also

http://www.nessus.org/u?69af359a

Plugin Details

Severity: High

ID: 26154

File Name: hpux_PHSS_36385.nasl

Version: 1.26

Type: local

Published: 9/25/2007

Updated: 1/11/2021

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

CVSS v2

Risk Factor: High

Base Score: 7.6

Temporal Score: 6.3

Vector: CVSS2#AV:N/AC:H/Au:N/C:C/I:C/A:C

Vulnerability Information

CPE: cpe:/o:hp:hp-ux

Required KB Items: Host/local_checks_enabled, Host/HP-UX/version, Host/HP-UX/swlist

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 7/18/2007

Vulnerability Publication Date: 12/5/2005

Exploitable With

Core Impact

Metasploit (Apache Module mod_rewrite LDAP Protocol Buffer Overflow)

Reference Information

CVE: CVE-2005-3352, CVE-2005-3357, CVE-2006-3747

BID: 15834, 16152, 19204

CWE: 189

HP: SSRT071293, emr_na-c01428449