Vulnerabilities > CVE-2010-3007 - Unspecified vulnerability in HP Data Protector Express 3.1/3.5/4.0

047910
CVSS 7.2 - HIGH
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
local
low complexity
hp
nessus
exploit available
metasploit

Summary

Unspecified vulnerability in HP Data Protector Express, and Data Protector Express Single Server Edition (SSE), 3.x before build 56936 and 4.x before build 56906 allows local users to gain privileges or cause a denial of service via unknown vectors.

Vulnerable Configurations

Part Description Count
Application
Hp
10

Exploit-Db

descriptionHP Data Protector DtbClsLogin Buffer Overflow. CVE-2010-3007. Remote exploit for windows platform
idEDB-ID:23290
last seen2016-02-02
modified2012-12-11
published2012-12-11
reportermetasploit
sourcehttps://www.exploit-db.com/download/23290/
titleHP Data Protector DtbClsLogin Buffer Overflow

Metasploit

descriptionThis module exploits a stack buffer overflow in HP Data Protector 4.0 SP1. The overflow occurs during the login process, in the DtbClsLogin function provided by the dpwindtb.dll component, where the Utf8Cpy (strcpy like function) is used in an insecure way with the username. A successful exploitation will lead to code execution with the privileges of the "dpwinsdr.exe" (HP Data Protector Express Domain Server Service) process, which runs as SYSTEM by default.
idMSF:EXPLOIT/WINDOWS/MISC/HP_DATAPROTECTOR_DTBCLSLOGIN
last seen2020-05-21
modified2017-07-24
published2012-12-11
references
reporterRapid7
sourcehttps://github.com/rapid7/metasploit-framework/blob/master//modules/exploits/windows/misc/hp_dataprotector_dtbclslogin.rb
titleHP Data Protector DtbClsLogin Buffer Overflow

Nessus

NASL familyWindows
NASL idHP_DATA_PROTECTOR_EXP_MULTIPLE.NASL
descriptionHP Data Protector Express is installed on the remote host. The installed version of the software is affected by multiple remote vulnerabilities including a buffer overflow and a NULL pointer deference. An attacker could leverage these vulnerabilities to execute remote code or cause a denial of service attack on the affected host.
last seen2020-06-01
modified2020-06-02
plugin id49645
published2010-09-22
reporterThis script is Copyright (C) 2010-2018 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/49645
titleHP Data Protector Express < 4.x build 56906 / 3.x build 56936 Multiple Vulnerabilities

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/118776/hp_dataprotector_dtbclslogin.rb.txt
idPACKETSTORM:118776
last seen2016-12-05
published2012-12-12
reporterAbdulAziz Hariri
sourcehttps://packetstormsecurity.com/files/118776/HP-Data-Protector-DtbClsLogin-Buffer-Overflow.html
titleHP Data Protector DtbClsLogin Buffer Overflow

Saint

bid43105
descriptionHP Data Protector Express DtbClsLogin function buffer overflow
osvdb67973
titlehp_data_protector_express_dtbclslogin
typeremote