HP-UX PHSS_36386 : HP OpenView Network Node Manager (OV NNM) Running Apache, Remote Cross Site Scripting (XSS), Denial of Service (DoS), Execute Arbitrary Code (HPSBMA02328 SSRT071293 rev.2)

High Nessus Plugin ID 26155

New! Vulnerability Priority Rating (VPR)

Tenable calculates a dynamic VPR for every vulnerability. VPR combines vulnerability information with threat intelligence and machine learning algorithms to predict which vulnerabilities are most likely to be exploited in attacks. Read more about what VPR is and how it's different from CVSS.

VPR Score: 4.9


The remote HP-UX host is missing a security-related patch.


s700_800 11.X IA-64 OV NNM7.51 Intermediate Patch 16 :

Potential vulnerabilities have been identified with HP OpenView Network Node Manager (OV NNM) running Apache. These vulnerabilities could be exploited remotely resulting in cross site scripting (XSS), Denial of Service (DoS), or execution of arbitrary code.


Install patch PHSS_36386 or subsequent.

See Also


Plugin Details

Severity: High

ID: 26155

File Name: hpux_PHSS_36386.nasl

Version: 1.25

Type: local

Published: 2007/09/25

Updated: 2018/07/12

Dependencies: 12634

Risk Information

Risk Factor: High

VPR Score: 4.9

CVSS v2.0

Base Score: 7.6

Temporal Score: 6.3

Vector: CVSS2#AV:N/AC:H/Au:N/C:C/I:C/A:C

Temporal Vector: CVSS2#E:F/RL:OF/RC:C

Vulnerability Information

CPE: cpe:/o:hp:hp-ux

Required KB Items: Host/local_checks_enabled, Host/HP-UX/version, Host/HP-UX/swlist

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 2007/07/18

Vulnerability Publication Date: 2005/12/05

Exploitable With

Core Impact

Metasploit (Apache Module mod_rewrite LDAP Protocol Buffer Overflow)

Reference Information

CVE: CVE-2005-3352, CVE-2005-3357, CVE-2006-3747

BID: 15834, 16152, 19204

HP: emr_na-c01428449, SSRT071293

CWE: 189