CVE-2009-4000
UnknownEPSS 21.24%
Last modified
CVE-2009-4000 is a vulnerability of currently unknown severity. Directory traversal vulnerability in goform/formExportDataLogs in HP Power Manager before 4.2.10 allows remote attackers to overwrite arbitrary files, and execute arbitrary code, via directory traversal sequences in the fileName parameter.. EPSS estimates a 21.24% chance of exploitation in the next 30 days.
Description
Directory traversal vulnerability in goform/formExportDataLogs in HP Power Manager before 4.2.10 allows remote attackers to overwrite arbitrary files, and execute arbitrary code, via directory traversal sequences in the fileName parameter.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Hp | Power Manager | <= 4.2.9 |
| Hp | Power Manager | 4.2.5 |
| Hp | Power Manager | 4.2.6 |
| Hp | Power Manager | 4.2.7 |
| Hp | Power Manager | 4.2.8 |
References
- http://marc.info/?l=bugtraq&m=126393370331959&w=2Vendor Advisory
- http://secunia.com/advisories/37280Vendor Advisory
- http://secunia.com/secunia_research/2009-48/Vendor Advisory
- http://marc.info/?l=bugtraq&m=126393370331959&w=2Vendor Advisory
- http://secunia.com/advisories/37280Vendor Advisory
- http://secunia.com/secunia_research/2009-48/Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2009-4000?
Directory traversal vulnerability in goform/formExportDataLogs in HP Power Manager before 4.2.10 allows remote attackers to overwrite arbitrary files, and execute arbitrary code, via directory traversal sequences in the fileName parameter.
How severe is CVE-2009-4000?
Severity scoring for CVE-2009-4000 is pending analysis. The EPSS model estimates a 21.24% probability of exploitation in the next 30 days.
How do I fix CVE-2009-4000?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2009
- CVE-2009-3993Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2009-3994Stack-based buffer overflow in the GetUID function in src-IL…
- CVE-2009-3995Multiple heap-based buffer overflows in IN_MOD.DLL (aka the …
- CVE-2009-3996Heap-based buffer overflow in IN_MOD.DLL (aka the Module Dec…
- CVE-2009-3997Integer overflow in IN_MOD.DLL (aka the Module Decoder Plug-…
- CVE-2009-3999Stack-based buffer overflow in goform/formExportDataLogs in …
- CVE-2009-4001Integer overflow in XnView before 1.97.2 might allow remote …
- CVE-2009-4002Heap-based buffer overflow in Adobe Shockwave Player before …
- CVE-2009-4003Multiple integer overflows in Adobe Shockwave Player before …
- CVE-2009-4004Buffer overflow in the kvm_vcpu_ioctl_x86_setup_mce function…7.8
- CVE-2009-4005The collect_rx_frame function in drivers/isdn/hisax/hfc_usb.…
- CVE-2009-4006Stack-based buffer overflow in the TEA decoding algorithm in…
Are you affected by CVE-2009-4000?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
