CVE-2009-0920
HP Network Node Manager 7.01, 7.51, 7.53 - Stack-Based Buffer Overflow via OvOSLocale Cookie
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2009-0920.
PoCs published by Metasploit, Oren Isacson, juan vazquez, including Metasploit module exploits/windows/http/hp_nnm_toolbar_02.
AI-analyzed exploit summary This Metasploit module exploits a stack buffer overflow in HP OpenView Network Node Manager by sending a maliciously crafted OvOSLocale cookie to Toolbar.exe, allowing arbitrary code execution. It includes targets for both NNM 7.0 and 7.53_01195 with specific bad character handling and alignment techniques.
Description
Stack-based buffer overflow in OvCgi/Toolbar.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via a long OvOSLocale cookie, a variant of CVE-2008-0067.
Exploits (2)
This Metasploit module exploits a stack buffer overflow in HP OpenView Network Node Manager by sending a maliciously crafted OvOSLocale cookie to Toolbar.exe, allowing arbitrary code execution. It includes targets for both NNM 7.0 and 7.53_01195 with specific bad character handling and alignment techniques.
This Metasploit module exploits a stack buffer overflow in HP OpenView Network Node Manager via a maliciously crafted OvOSLocale cookie. It targets specific builds (7.0 and 7.53_01195) to achieve remote code execution by overwriting EIP and aligning registers for shellcode execution.