| VID |
29085 |
| Severity |
40 |
| Port |
8000 |
| Protocol |
TCP |
| Class |
WWW |
| Detailed Description |
The HP Web Jetadmin is vulnerable to multiple vulnerabilities. HP JetAdmin versions 7.0 and earlier could allow a remote attacker to execute programs installed on the vulnerable system. This vulnerability is due to a failure of the application to properly validate and sanitize user supplied input. Successful exploitation of this vulnerability could allow a remote attacker to execute arbitrary commands on the affected system with SYSTEM level or root privileges.
* References: http://archives.neohapsis.com/archives/bugtraq/2004-04/0359.html http://www.ciac.org/ciac/bulletins/o-136.shtml http://packetstormsecurity.nl/0404-advisories/HP_Web_Jetadmin_advisory.txt http://www.phenoelit.de/stuff/HP_Web_Jetadmin_advisory.txt http://www.securitytracker.com/alerts/2004/Apr/1009960.html
* Platforms Affected: Hewlett-Packard HP JetAdmin 6.2 and earlier Hewlett-Packard HP JetAdmin 6.5 Hewlett-Packard HP JetAdmin 7.0 Any operating system Any version |
| Recommendation |
Upgrade to the latest version of HP Web Jetadmin (7.5 or later), available from the Hewlett-Packard Web site at http://www.hp.com/ |
| Related URL |
(CVE) |
| Related URL |
10224 (SecurityFocus) |
| Related URL |
15989 (ISS) |
|