>> HP OpenView Storage Data Protector Backup Agents Command Execution Vulnerability
Title : HP OpenView Storage Data Protector Backup Agents Command Execution Vulnerability VUPEN ID : VUPEN/ADV-2006-3273 CVE ID : CVE-2006-4201
Rated as : High Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2006-08-14
Technical Description
A vulnerability has been identified in HP OpenView Storage Data Protector, which could be exploited by remote attackers to execute arbitrary commands. This flaw is due to a combination of bad authentication mechanisms and input validation errors in the backup agents when communicating with the central backup server (Cell Manager), which could be exploited by unauthenticated attackers to compromise a vulnerable system.