Vulnerabilities > CVE-2013-4822 - Unspecified vulnerability in HP products
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Unspecified vulnerability in HP Intelligent Management Center (iMC) and HP IMC Branch Intelligent Management System Software Module (aka BIMS) allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1606.
Vulnerable Configurations
D2sec
name | HP Intelligent Management Center BIMS UploadServlet File Upload |
url | http://www.d2sec.com/exploits/hp_intelligent_management_center_bims_uploadservlet_file_upload.html |
Exploit-Db
description | HP Intelligent Management Center BIms UploadServlet Directory Traversal. CVE-2013-4822. Remote exploit for windows platform |
id | EDB-ID:29130 |
last seen | 2016-02-03 |
modified | 2013-10-22 |
published | 2013-10-22 |
reporter | metasploit |
source | https://www.exploit-db.com/download/29130/ |
title | HP Intelligent Management Center BIms UploadServlet Directory Traversal |
Metasploit
description | This module exploits a directory traversal vulnerability on the version 5.2 of the BIMS component from the HP Intelligent Management Center. The vulnerability exists in the UploadServlet, allowing the user to download and upload arbitrary files. This module has been tested successfully on HP Intelligent Management Center with BIMS 5.2 E0401 on Windows 2003 SP2. |
id | MSF:EXPLOIT/WINDOWS/HTTP/HP_IMC_BIMS_UPLOAD |
last seen | 2020-06-02 |
modified | 2017-07-24 |
published | 2013-10-19 |
references | |
reporter | Rapid7 |
source | https://github.com/rapid7/metasploit-framework/blob/master//modules/exploits/windows/http/hp_imc_bims_upload.rb |
title | HP Intelligent Management Center BIMS UploadServlet Directory Traversal |
Nessus
NASL family | Misc. |
NASL id | HP_IMC_BIMS_52_E401.NASL |
description | The version of the HP Intelligent Management Center Branch Intelligent Management System module on the remote host is a version prior to 5.2 E0401 and is potentially affected by multiple vulnerabilities : - The |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 71891 |
published | 2014-01-09 |
reporter | This script is Copyright (C) 2014-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/71891 |
title | HP Intelligent Management Center Branch Intelligent Management Module Multiple Vulnerabilities |
code |
|
Packetstorm
data source | https://packetstormsecurity.com/files/download/123708/hp_imc_bims_upload.rb.txt |
id | PACKETSTORM:123708 |
last seen | 2016-12-05 |
published | 2013-10-22 |
reporter | rgod |
source | https://packetstormsecurity.com/files/123708/HP-Intelligent-Management-Center-BIMS-UploadServlet-Directory-Traversal.html |
title | HP Intelligent Management Center BIMS UploadServlet Directory Traversal |
References
- https://h20564.www2.hp.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c03943425
- https://h20564.www2.hp.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c03943425
- https://h20564.www2.hp.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c03943425
- https://h20564.www2.hp.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c03943425