HP-UX PHSS_36385 : HP OpenView Network Node Manager (OV NNM) Running Apache, Remote Cross Site Scripting (XSS), Denial of Service (DoS), Execute Arbitrary Code (HPSBMA02328 SSRT071293 rev.2)

High Nessus Plugin ID 26154


The remote HP-UX host is missing a security-related patch.


s700_800 11.X PA-RISC OV NNM7.51 Intermediate Patch 16 :

Potential vulnerabilities have been identified with HP OpenView Network Node Manager (OV NNM) running Apache. These vulnerabilities could be exploited remotely resulting in cross site scripting (XSS), Denial of Service (DoS), or execution of arbitrary code.


Install patch PHSS_36385 or subsequent.

See Also


Plugin Details

Severity: High

ID: 26154

File Name: hpux_PHSS_36385.nasl

Version: 1.25

Type: local

Published: 2007/09/25

Updated: 2018/07/12

Dependencies: 12634

Risk Information

Risk Factor: High

CVSS v2.0

Base Score: 7.6

Temporal Score: 6.3

Vector: CVSS2#AV:N/AC:H/Au:N/C:C/I:C/A:C

Temporal Vector: CVSS2#E:F/RL:OF/RC:C

Vulnerability Information

CPE: cpe:/o:hp:hp-ux

Required KB Items: Host/local_checks_enabled, Host/HP-UX/version, Host/HP-UX/swlist

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 2007/07/18

Vulnerability Publication Date: 2005/12/05

Exploitable With

Core Impact

Metasploit (Apache Module mod_rewrite LDAP Protocol Buffer Overflow)

Reference Information

CVE: CVE-2005-3352, CVE-2005-3357, CVE-2006-3747

BID: 15834, 16152, 19204

HP: emr_na-c01428449, SSRT071293

CWE: 189