HP_Data_Protector_Backup_Client_Service_GET_FILE_Directory_Traversal_attack

Strike ID:
G11-4c801
CVSS:
8.5 (AV:N/AC:L/Au:N/C:C/I:N/A:P)
False Positive:
f
Variants:
1
Year:
2011

Description

A directory traversal vulnerability exists in HP Data Protector Backup Client Service. The vulnerability is due to insufficient sanitization in the processing of the GET_FILE messages. Remote unauthenticated attackers could exploit this vulnerability by sending a crafted request message to the target service. Successful exploitation would allow attackers to download and view arbitrary files from the target server.

CVE

Bid