Exploitation Summary
EIP tracks 3 public exploits for CVE-2009-4178.
PoCs published by Metasploit, S2 Crew, MC, including Metasploit module exploits/windows/http/hp_nnm_ovwebhelp.
AI-analyzed exploit summary This Metasploit module exploits a stack buffer overflow in HP OpenView Network Node Manager 7.50 via a crafted POST request to OvWebHelp.exe. It achieves remote code execution by overflowing the buffer with a malicious payload.
Description
Heap-based buffer overflow in OvWebHelp.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via a long Topic parameter.
Exploits (3)
This Metasploit module exploits a stack buffer overflow in HP OpenView Network Node Manager 7.50 via a crafted POST request to OvWebHelp.exe. It achieves remote code execution by overflowing the buffer with a malicious payload.
This exploit targets a buffer overflow vulnerability in HP OpenView NNM OvWebHelp.exe CGI. It sends a maliciously crafted POST request with a long 'Topic' parameter to trigger a stack-based overflow, executing shellcode that spawns a reverse shell.
This Metasploit module exploits a stack buffer overflow in HP OpenView Network Node Manager 7.50 via a crafted POST request to OvWebHelp.exe. It leverages a known return address in ov.dll to execute arbitrary payloads.