CVE-2009-2685
HP Power Manager - Stack-based Buffer Overflow via Login Variable
Title source: llmExploitation Summary
EIP tracks 3 public exploits for CVE-2009-2685.
PoCs published by Metasploit, ryujin, MC, sinn3r, including Metasploit module exploits/windows/http/hp_power_manager_login.
AI-analyzed exploit summary This Metasploit module exploits a stack buffer overflow in HP Power Manager 4.2 via a crafted POST request with an overly long Login string, leading to arbitrary code execution.
Description
Stack-based buffer overflow in the login form in the management web server in HP Power Manager allows remote attackers to execute arbitrary code via the Login variable.
Exploits (3)
This Metasploit module exploits a stack buffer overflow in HP Power Manager 4.2 via a crafted POST request with an overly long Login string, leading to arbitrary code execution.
This exploit targets a buffer overflow vulnerability in HP Power Manager Administration via a crafted HTTP POST request. It leverages a JMP ESP instruction from MSVCP60.dll and includes alphanumeric shellcode to spawn a reverse shell.
This Metasploit module exploits a stack buffer overflow in Hewlett-Packard Power Manager 4.2 via a crafted POST request with an overly long Login string. It uses an egghunter and alphanumeric encoding to achieve remote code execution.