Exploitation Summary
EIP tracks 3 public exploits for CVE-2009-4179.
PoCs published by Metasploit, sinn3r & muts, jduck, including Metasploit module exploits/windows/http/hp_nnm_ovalarm_lang.
AI-analyzed exploit summary This Metasploit module exploits a stack buffer overflow in HP OpenView Network Node Manager 7.53 via a crafted HTTP request with a long 'Accept-Language' header and 'OVABverbose' parameter, leading to arbitrary code execution.
Description
Stack-based buffer overflow in ovalarm.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via a long HTTP Accept-Language header in an OVABverbose action.
Exploits (3)
This Metasploit module exploits a stack buffer overflow in HP OpenView Network Node Manager 7.53 via a crafted HTTP request with a long 'Accept-Language' header and 'OVABverbose' parameter, leading to arbitrary code execution.
This exploit targets a buffer overflow vulnerability in HP OpenView Network Node Manager (NNM) 7.53 via the ovalarm.exe CGI. It sends a crafted HTTP request with a malicious payload to achieve remote code execution (RCE) by overwriting the EIP and executing shellcode.
This Metasploit module exploits a stack buffer overflow in HP OpenView Network Node Manager 7.53 via a crafted HTTP request with a long 'Accept-Language' header and 'OVABverbose' parameter, leading to arbitrary code execution.