PT-2004-2756 · Hewlett Packard · Hp Web Jetadmin
Wirepair
·
Published
2004-03-24
·
Updated
2017-07-11
·
CVE-2004-1857
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
HP Web Jetadmin version 7.5.2546
Description
A directory traversal issue exists in the setinfo.hts file, allowing remote authenticated attackers to read arbitrary files. This is achieved by including a .. (dot dot) in the
setinclude parameter.Recommendations
For HP Web Jetadmin version 7.5.2546, avoid using the
setinclude parameter with .. (dot dot) sequences until a patch is available. As a temporary workaround, consider restricting access to the setinfo.hts file to minimize the risk of exploitation.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Hp Web Jetadmin