CVE-2010-1555
published 2010-05-13CVE-2010-1555: Stack-based buffer overflow in getnnmdata.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary…
PriorityP275critical10CVSS 2.0
AVNACLAuNCCICAC
EXPLOIT
EPSS
64.45%
99.1th percentile
Stack-based buffer overflow in getnnmdata.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via an invalid Hostname parameter.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| hp | openview_network_node_manager | — | — |
| hp | openview_network_node_manager | — | — |
| hp | openview_network_node_manager | — | — |
Detection & IOCsextracted from sources · hover to see the quote
bytes↗
\xeb\x03\x59\xeb\x05\xe8\xf8\xff\xff\xff
bytes↗
\x66\x81\xca\xff\x0f\x42\x52\x6a\x02\x58\xcd\x2e\x3c\x05\x5a\x74
- →Detect HTTP POST requests to /OvCgi/getnnmdata.exe with an abnormally large Hostname parameter (>2038 bytes) indicative of buffer overflow exploitation. ↗
- →Alert on HTTP POST requests to /OvCgi/getnnmdata.exe where the User-Agent string contains 'T00WT00W' or embedded shellcode bytes. ↗
- →Detect SEH-based exploit pattern: look for the egg-hunter stub bytes \x66\x81\xca\xff\x0f\x42\x52\x6a\x02\x58\xcd\x2e\x3c\x05\x5a\x74 in HTTP POST body to getnnmdata.exe. ↗
- →The exploit uses AlphanumUpper encoded payload with ECX as BufferRegister; look for large all-uppercase alphanumeric payloads in the Hostname POST parameter. ↗
- →Known exploit return addresses for pop-pop-ret gadgets: 0x5a01f277 (NNM 7.50), 0x5a666d69 (NNM 7.53), 0x5A667A77 (NNM 7.53 alternate); presence in network traffic to port 80 targeting getnnmdata.exe is highly suspicious. ↗
- ·The exploit targets HP OV NNM versions 7.50 and 7.53 specifically; the CVE also covers 7.01 and 7.51 but no public exploit offsets/return addresses are provided for those versions. ↗
- ·The standalone Python PoC embeds shellcode (calc.exe launcher) directly in the User-Agent header, an unusual delivery vector that may bypass body-only inspection rules. ↗
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Suricata
ET WEB_SPECIFIC_APPS Minerva mod SQL Injection Attempt -- forum.php c UPDATE
suricata·2010-07-30·CVSS 7.5
CVE-2007-1555 [HIGH] ET WEB_SPECIFIC_APPS Minerva mod SQL Injection Attempt -- forum.php c UPDATE
ET WEB_SPECIFIC_APPS Minerva mod SQL Injection Attempt -- forum.php c UPDATE
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS Minerva mod SQL Injection Attempt -- forum.php c UPDATE"; flow:established,to_server; http.uri; content:"/forum.php?"; nocase; content:"c="; nocase; content:"UPDATE"; nocase; content:"SET"; nocase; distance:0; reference:cve,CVE-2007-1555; reference:url,www.milw0rm.com/exploits/3519; classtype:web-application-attack; sid:2004169; rev:8; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_03, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_t
Suricata
ET WEB_SPECIFIC_APPS Minerva mod SQL Injection Attempt -- forum.php c ASCII
suricata·2010-07-30·CVSS 7.5
CVE-2007-1555 [HIGH] ET WEB_SPECIFIC_APPS Minerva mod SQL Injection Attempt -- forum.php c ASCII
ET WEB_SPECIFIC_APPS Minerva mod SQL Injection Attempt -- forum.php c ASCII
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS Minerva mod SQL Injection Attempt -- forum.php c ASCII"; flow:established,to_server; http.uri; content:"/forum.php?"; nocase; content:"c="; nocase; content:"ASCII("; nocase; content:"SELECT"; nocase; distance:0; reference:cve,CVE-2007-1555; reference:url,www.milw0rm.com/exploits/3519; classtype:web-application-attack; sid:2004168; rev:9; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_11_19, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_
Suricata
ET WEB_SPECIFIC_APPS Minerva mod SQL Injection Attempt -- forum.php c DELETE
suricata·2010-07-30·CVSS 7.5
CVE-2007-1555 [HIGH] ET WEB_SPECIFIC_APPS Minerva mod SQL Injection Attempt -- forum.php c DELETE
ET WEB_SPECIFIC_APPS Minerva mod SQL Injection Attempt -- forum.php c DELETE
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS Minerva mod SQL Injection Attempt -- forum.php c DELETE"; flow:established,to_server; http.uri; content:"/forum.php?"; nocase; content:"c="; nocase; content:"DELETE"; nocase; content:"FROM"; nocase; distance:0; reference:cve,CVE-2007-1555; reference:url,www.milw0rm.com/exploits/3519; classtype:web-application-attack; sid:2004167; rev:8; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_03, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_
Suricata
ET WEB_SPECIFIC_APPS Minerva mod SQL Injection Attempt -- forum.php c SELECT
suricata·2010-07-30·CVSS 7.5
CVE-2007-1555 [HIGH] ET WEB_SPECIFIC_APPS Minerva mod SQL Injection Attempt -- forum.php c SELECT
ET WEB_SPECIFIC_APPS Minerva mod SQL Injection Attempt -- forum.php c SELECT
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS Minerva mod SQL Injection Attempt -- forum.php c SELECT"; flow:established,to_server; http.uri; content:"/forum.php?"; nocase; content:"c="; nocase; content:"SELECT"; nocase; content:"FROM"; nocase; distance:0; reference:cve,CVE-2007-1555; reference:url,www.milw0rm.com/exploits/3519; classtype:web-application-attack; sid:2004164; rev:8; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_03, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_
Suricata
ET WEB_SPECIFIC_APPS Minerva mod SQL Injection Attempt -- forum.php c INSERT
suricata·2010-07-30·CVSS 7.5
CVE-2007-1555 [HIGH] ET WEB_SPECIFIC_APPS Minerva mod SQL Injection Attempt -- forum.php c INSERT
ET WEB_SPECIFIC_APPS Minerva mod SQL Injection Attempt -- forum.php c INSERT
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS Minerva mod SQL Injection Attempt -- forum.php c INSERT"; flow:established,to_server; http.uri; content:"/forum.php?"; nocase; content:"c="; nocase; content:"INSERT"; nocase; content:"INTO"; nocase; distance:0; reference:cve,CVE-2007-1555; reference:url,www.milw0rm.com/exploits/3519; classtype:web-application-attack; sid:2004166; rev:8; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_03, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_
Suricata
ET WEB_SPECIFIC_APPS Minerva mod SQL Injection Attempt -- forum.php c UNION SELECT
suricata·2010-07-30·CVSS 7.5
CVE-2007-1555 [HIGH] ET WEB_SPECIFIC_APPS Minerva mod SQL Injection Attempt -- forum.php c UNION SELECT
ET WEB_SPECIFIC_APPS Minerva mod SQL Injection Attempt -- forum.php c UNION SELECT
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS Minerva mod SQL Injection Attempt -- forum.php c UNION SELECT"; flow:established,to_server; http.uri; content:"/forum.php?"; nocase; content:"c="; nocase; content:"UNION"; nocase; content:"SELECT"; nocase; distance:0; pcre:"/UNION\s+SELECT/i"; reference:cve,CVE-2007-1555; reference:url,www.milw0rm.com/exploits/3519; classtype:web-application-attack; sid:2004165; rev:8; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_03, mitre_tactic_id TA0001, mitre_tactic_name Initial_A
Exploit-DB
HP OpenView Network Node Manager (OV NNM) - 'getnnmdata.exe Hostname' CGI Buffer Overflow (Metasploit)
exploitdb·2011-03-25
CVE-2010-1555 HP OpenView Network Node Manager (OV NNM) - 'getnnmdata.exe Hostname' CGI Buffer Overflow (Metasploit)
HP OpenView Network Node Manager (OV NNM) - 'getnnmdata.exe Hostname' CGI Buffer Overflow (Metasploit)
---
##
# $Id: hp_nnm_getnnmdata_hostname.rb 12131 2011-03-25 00:46:59Z mc $
##
##
# This file is part of the Metasploit Framework and may be subject to
# redistribution and commercial restrictions. Please see the Metasploit
# Framework web site for more information on licensing and terms of use.
# http://metasploit.com/framework/
##
require 'msf/core'
class Metasploit3 'HEAD', :uri => '/OvCgi/getnnmdata.exe', :pattern => /Hewlett-Packard Development Company/ }
include Msf::Exploit::Remote::HttpClient
include Msf::Exploit::Remote::Seh
def initialize(info = {})
super(update_info(info,
'Name' => 'HP OpenView Network Node Manager getnnmdata.exe (Hostname) CGI Buffer Overflow',
'Descrip
Exploit-DB
HP OpenView Network Node Manager (OV NNM) - 'getnnmdata.exe' CGI Invalid Hostname Remote Code Execution
exploitdb·2010-07-02·CVSS 10.0
CVE-2010-1555 [CRITICAL] HP OpenView Network Node Manager (OV NNM) - 'getnnmdata.exe' CGI Invalid Hostname Remote Code Execution
HP OpenView Network Node Manager (OV NNM) - 'getnnmdata.exe' CGI Invalid Hostname Remote Code Execution
---
# Exploit Title: HP OpenView NNM getnnmdata.exe CGI Invalid Hostname Remote Code Execution
# Date: 2010.07.02
# Author: S2 Crew [Hungary]
# Software Link: hp.com
# Version: 7.53
# Tested on: Windows 2003
# CVE: CVE-2010-1555
# Code :
#!/usr/bin/python
import struct
import socket
import httplib
import urllib
eh =(
"\x50\x59\x49\x49\x49\x49\x49\x49\x49\x49\x49\x49\x51\x5a"
"\x56\x54\x58\x33\x30\x56\x58\x34\x41\x50\x30\x41\x33\x48"
"\x48\x30\x41\x30\x30\x41\x42\x41\x41\x42\x54\x41\x41\x51"
"\x32\x41\x42\x32\x42\x42\x30\x42\x42\x58\x50\x38\x41\x43"
"\x4a\x4a\x49\x42\x46\x4d\x51\x49\x5a\x4b\x4f\x44\x4f\x50"
"\x42\x46\x32\x42\x4a\x43\x32\x50\x58\x48\x4d\x46\x4e\x47"
"\x4c\x43\x35\x50
Metasploit
HP OpenView Network Node Manager getnnmdata.exe (Hostname) CGI Buffer Overflow
metasploit
HP OpenView Network Node Manager getnnmdata.exe (Hostname) CGI Buffer Overflow
HP OpenView Network Node Manager getnnmdata.exe (Hostname) CGI Buffer Overflow
This module exploits a buffer overflow in HP OpenView Network Node Manager 7.50/7.53. By sending specially crafted Hostname parameter to the getnnmdata.exe CGI, an attacker may be able to execute arbitrary code.
No writeups or analysis indexed.
http://marc.info/?l=bugtraq&m=127360750704351&w=2http://www.securityfocus.com/archive/1/511250/100/0/threadedhttp://www.securityfocus.com/bid/40072http://zerodayinitiative.com/advisories/ZDI-10-086/http://marc.info/?l=bugtraq&m=127360750704351&w=2http://www.securityfocus.com/archive/1/511250/100/0/threadedhttp://www.securityfocus.com/bid/40072http://zerodayinitiative.com/advisories/ZDI-10-086/
2010-05-13
Published