An information disclosure vulnerability exists in the BIMS add-in module of HP Intelligent Management Center. The vulnerability is due to lack of authentication and insufficient input validation in the UploadServlet servlet when processing HTTP request parameters. By sending crafted HTTP requests to the target system, a remote unauthenticated attacker can leverage this vulnerability to view the contents of arbitrary files on a target system.
Category Archives: Checkpoint
Checkpoint
Adobe Multiple Products Flash Content Parsing Code Execution (APSA10-03: CVE-2010-2884) (CVE-2010-2884)
A remote code execution vulnerability has been reported in multiple Adobe products. The vulnerability is due to an error in the way Flash files are parsed.
Adobe Flash Player and AIR Security Bypass (APSB14-18; CVE-2014-0541)
A security bypass vulnerability has been reported in Adobe Flash Player. The vulnerability is due to insufficient security restrictions while handling specially crafted SWF files. A remote attacker can exploit this vulnerability by enticing a target user to open a specially crafted SWF file using an affected version of Adobe Flash Player.
MOXA Device Manager Tool SCADA Buffer Overflow (CVE-2010-4741)
A remote code execution vulnerability has been reported in MOXA Device Manager Tool. The vulnerability is due to a stack based buffer overflow when handling specially crafted packets.
HP Data Protector Opcode 28 and 11 Command Execution (CVE-2014-2623)
A command execution vulnerability exists in Hewlett-Packard Data Protector. The vulnerability is due to a design weakness when handling requests to port 5555. A remote attacker can exploit this vulnerability by sending crafted packets to the target service. Successful exploitation could lead to arbitrary command execution with system privileges on the target server.