PT-2004-2756 · Hewlett Packard · Hp Web Jetadmin

Wirepair

·

Published

2004-03-24

·

Updated

2017-07-11

·

CVE-2004-1857

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions HP Web Jetadmin version 7.5.2546
Description A directory traversal issue exists in the setinfo.hts file, allowing remote authenticated attackers to read arbitrary files. This is achieved by including a .. (dot dot) in the setinclude parameter.
Recommendations For HP Web Jetadmin version 7.5.2546, avoid using the setinclude parameter with .. (dot dot) sequences until a patch is available. As a temporary workaround, consider restricting access to the setinfo.hts file to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-1857

Affected Products

Hp Web Jetadmin