HP System Management Homepage < 6.3 Multiple Vulnerabilities

critical Nessus Plugin ID 53532
New! Plugin Severity Now Using CVSS v3

The calculated severity for Plugins has been updated to use CVSS v3 by default. Plugins that do not have a CVSS v3 score will fall back to CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.


The remote web server is affected by multiple vulnerabilities.


According to the web server's banner, the version of HP System Management Homepage (SMH) hosted on the remote host is earlier than 6.3. Such versions are reportedly affected by the following vulnerabilities :

- An error exists in the function 'fnmatch' in the bundled version of PHP that can lead to stack exhaustion. (CVE-2010-1917)

- An information disclosure vulnerability exists in the 'var_export' function in the bundled version of PHP that can be triggered when handling certain error conditions. (CVE-2010-2531)

- A double free vulnerability in the 'ssl3_get_key_exchange()' function in the third-party OpenSSL library could be abused to crash the application. (CVE-2010-2939)

- A format string vulnerability in the phar extension in the bundled version of PHP could lead to the disclosure of memory contents and possibly allow execution of arbitrary code via a specially crafted 'phar://' URI. (CVE-2010-2950)

- A NULL pointer dereference in 'ZipArchive::getArchiveComment' included with the bundled version of PHP can be abused to crash the application. (CVE-2010-3709)

- The bundled version of libxml2 may read from invalid memory locations when processing malformed XPath expressions, resulting in an application crash.

- An error in the 'mb_strcut()' function in the bundled version of PHP can be exploited by passing a large 'length' parameter to disclose potentially sensitive information from the heap. (CVE-2010-4156)

- An as-yet unspecified remote code execution vulnerability could allow an authenticated user to execute arbitrary code with system privileges.

- An as-yet unspecified, unauthorized access vulnerability could lead to a complete system compromise.


Upgrade to HP System Management Homepage 6.3 or later.

See Also


Plugin Details

Severity: Critical

ID: 53532

File Name: hpsmh_6_3_0_22.nasl

Version: 1.12

Type: remote

Family: Web Servers

Published: 4/22/2011

Updated: 11/15/2018

Dependencies: compaq_wbem_detect.nasl

Risk Information


Risk Factor: Medium

Score: 5.9


Risk Factor: Critical

Base Score: 10

Temporal Score: 7.8

Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Temporal Vector: E:POC/RL:OF/RC:C

Vulnerability Information

CPE: cpe:/a:hp:system_management_homepage

Required KB Items: www/hp_smh

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 4/19/2011

Vulnerability Publication Date: 5/11/2010

Reference Information

CVE: CVE-2010-1917, CVE-2010-2531, CVE-2010-2939, CVE-2010-2950, CVE-2010-3709, CVE-2010-4008, CVE-2010-4156, CVE-2011-1540, CVE-2011-1541

BID: 41991, 44718, 44727, 44779, 47507, 47512