PT-2013-4487 · Hewlett Packard · Hp Insight Diagnostics

Markus Wulftange

·

Published

2013-06-14

·

Updated

2013-06-14

·

CVE-2013-3575

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions HP Insight Diagnostics version 9.4.0.4710
Description The issue is related to the improper restriction of PHP include or require statements in the hpdiags/frontend2/help/pageview.php file. This allows remote attackers to include arbitrary .html files via the path parameter.
Recommendations For HP Insight Diagnostics version 9.4.0.4710, consider restricting access to the hpdiags/frontend2/help/pageview.php file until a patch is available. As a temporary workaround, avoid using the path parameter in the affected file to minimize the risk of exploitation.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-3575

Affected Products

Hp Insight Diagnostics