CVE-2011-0266
HP OpenView Network Node Manager 7.51 and 7.53 - Buffer Overflow via Long nameParams Parameter
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2011-0266.
PoCs published by Metasploit, sinn3r, MC, including Metasploit module exploits/windows/http/hp_nnm_nnmrptconfig_nameparams.
AI-analyzed exploit summary This Metasploit module exploits a stack-based buffer overflow in HP OpenView NNM's nnmRptConfig.exe via a maliciously crafted POST request with an overly long 'nameParams' parameter. It leverages SEH overwrites to achieve arbitrary code execution on Windows Server 2003 Enterprise.
Description
Buffer overflow in nnmRptConfig.exe in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via a long nameParams parameter, a different vulnerability than CVE-2011-0267.2.
Exploits (2)
This Metasploit module exploits a stack-based buffer overflow in HP OpenView NNM's nnmRptConfig.exe via a maliciously crafted POST request with an overly long 'nameParams' parameter. It leverages SEH overwrites to achieve arbitrary code execution on Windows Server 2003 Enterprise.
This Metasploit module exploits a stack-based buffer overflow in HP OpenView NNM's nnmRptConfig.exe via a maliciously crafted POST request with an overly long 'nameParams' parameter. It achieves remote code execution by overwriting the SEH chain or EIP, depending on the target version.