← All CVEs

CVE-2013-4811

high · 10

UpdateDomainControllerServlet in the SNAC registration server in HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, and Identity Driven Manager (IDM) 4.0 does not properly validate the adCert argument, which allows remote attackers to upload .jsp files and consequently execute arbitrary code via unspecified vectors, aka ZDI-CAN-1743.

10
CVSS
71.3%
EPSS (exploit prob.)
99th
EPSS percentile
2013-09-16
Published

AV:N/AC:L/Au:N/C:C/I:C/A:C

Weaknesses

CWE-20

Affected products

VendorProductAffected versions
hpidentity_driven_manager4.0
hpprocurve_manager3.20
hpprocurve_manager4.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2013-4811