Vulnerability Details CVE-2011-0924
The client in HP Data Protector does not verify the contents of files associated with the EXEC_CMD command, which allows remote attackers to execute arbitrary script code by providing this code with a trusted filename, as demonstrated by omni_chk_ds.sh.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.134
EPSS Ranking 93.8%
CVSS Severity
CVSS v2 Score 10.0
Products affected by CVE-2011-0924
-
cpe:2.3:a:hp:data_protector:6.10
-
cpe:2.3:a:hp:data_protector:6.11
-
cpe:2.3:a:hp:data_protector:7.0
-
cpe:2.3:a:hp:data_protector:7.03
-
cpe:2.3:a:hp:data_protector:7.03_108
-
cpe:2.3:a:hp:data_protector:8.0
-
cpe:2.3:a:hp:data_protector:8.14
-
cpe:2.3:a:hp:data_protector:8.15
-
cpe:2.3:a:hp:data_protector:8.17
-
cpe:2.3:a:hp:data_protector:9.0
-
cpe:2.3:a:hp:data_protector:9.05
-
cpe:2.3:a:hp:data_protector:9.06
-
cpe:2.3:a:hp:data_protector:9.09