Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The client in HP Data Protector does not verify the contents of files associated with the EXEC_CMD command, which allows remote attackers to execute arbitrary script code by providing this code with a trusted filename, as demonstrated by omni_chk_ds.sh.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
HP Data Protector客户端任意脚本代码执行漏洞
Vulnerability Description
HP Data Protector 是一款成熟的企业级数据保护平台,可不受距离限制通过磁盘或磁带自动执行高性能备份和恢复。 HP Data Protector中的客户端没有验证和EXEC_CMD命令有关的文件内容。远程攻击者可以通过提供带有信任文件名称的脚本代码,从而执行任意脚本代码。
CVSS Information
N/A
Vulnerability Type
N/A