Exploitation Summary
EIP tracks 2 public exploits for CVE-2010-3007.
PoCs published by Metasploit, AbdulAziz Hariri, juan vazquez, including Metasploit module exploits/windows/misc/hp_dataprotector_dtbclslogin.
AI-analyzed exploit summary This Metasploit module exploits a stack buffer overflow in HP Data Protector 4.0 SP1 during the login process, leveraging an insecure use of Utf8Cpy in the DtbClsLogin function. It achieves remote code execution with SYSTEM privileges by sending a maliciously crafted authentication request.
Description
Unspecified vulnerability in HP Data Protector Express, and Data Protector Express Single Server Edition (SSE), 3.x before build 56936 and 4.x before build 56906 allows local users to gain privileges or cause a denial of service via unknown vectors.
Exploits (2)
This Metasploit module exploits a stack buffer overflow in HP Data Protector 4.0 SP1 during the login process, leveraging an insecure use of Utf8Cpy in the DtbClsLogin function. It achieves remote code execution with SYSTEM privileges by sending a maliciously crafted authentication request.
This Metasploit module exploits a stack buffer overflow in HP Data Protector 4.0 SP1 during the login process via the DtbClsLogin function. It leverages an insecure use of Utf8Cpy (strcpy-like function) with the username to achieve remote code execution with SYSTEM privileges.