CVE-2012-3260
published 2012-09-25CVE-2012-3260: Unspecified vulnerability in a SOAP feature in HP SiteScope 11.10 through 11.12 allows remote attackers to execute arbitrary code via unknown vectors, aka…
PriorityP272critical10CVSS 2.0
AVNACLAuNCCICAC
EXPLOIT
EPSS
40.23%
98.5th percentile
Unspecified vulnerability in a SOAP feature in HP SiteScope 11.10 through 11.12 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1462.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| hp | sitescope | — | — |
| hp | sitescope | — | — |
| hp | sitescope | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor for unauthenticated SOAP requests to the APIPreferenceImpl AXIS service endpoint, particularly 'create' operations with empty or null credentials, which indicate authentication bypass attempts. ↗
- →Alert on file uploads to UploadManagerServlet, especially JSP payloads uploaded by newly created or anonymous accounts following an APIPreferenceImpl SOAP interaction. ↗
- →The exploit chain involves two distinct steps: (1) auth bypass via SOAP to create an account, then (2) JSP webshell upload via UploadManagerServlet — correlate these two events in sequence from the same source IP. ↗
- ·The CVE description references a SOAP feature vulnerability (ZDI-CAN-1462) in HP SiteScope 11.10–11.12, but the Metasploit module targets SiteScope 11.20 — the exact affected version range for this specific exploit chain may differ from the CVE's stated scope. ↗
- ·The NVD entry describes the attack vectors as 'unknown', limiting the ability to build precise signatures from the CVE description alone; operational indicators are derived from the Metasploit module implementation. ↗
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No writeups or analysis indexed.
2012-09-25
Published