Exploitation Summary
EIP tracks 3 public exploits for CVE-2010-1555.
PoCs published by Metasploit, S2 Crew, MC, including Metasploit module exploits/windows/http/hp_nnm_getnnmdata_hostname.
AI-analyzed exploit summary This Metasploit module exploits a buffer overflow in HP OpenView Network Node Manager via a maliciously crafted Hostname parameter in a POST request to getnnmdata.exe. It leverages SEH overwrites and alphanumeric shellcode to achieve remote code execution.
Description
Stack-based buffer overflow in getnnmdata.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via an invalid Hostname parameter.
Exploits (3)
This Metasploit module exploits a buffer overflow in HP OpenView Network Node Manager via a maliciously crafted Hostname parameter in a POST request to getnnmdata.exe. It leverages SEH overwrites and alphanumeric shellcode to achieve remote code execution.
This exploit targets a buffer overflow vulnerability in HP OpenView NNM's getnnmdata.exe CGI. It crafts a malicious HTTP POST request with a long 'Hostname' parameter to trigger remote code execution, executing a calc.exe payload via shellcode.
This Metasploit module exploits a buffer overflow in HP OpenView Network Node Manager via a crafted Hostname parameter in a POST request to getnnmdata.exe. It uses SEH overwrites and alphanumeric shellcode to achieve remote code execution.