APP: HP Data Protector LogClientInstallation SQL Injection

This signature detects attempts to exploit a known vulnerability in HP Data Protector. Attackers can execute arbitrary SQL commands on the server.

Extended Description

Unspecified vulnerability in HP Data Protector Notebook Extension 6.20 and Data Protector for Personal Computers 7.0 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1222.

Affected Products

Hp data_protector_notebook_extension

References

CVE: CVE-2011-3156

Short Name
APP:HP-DATA-PROTECTOR-SQL
Severity
Major
Recommended
False
Recommended Action
Drop
Category
APP
Keywords
CVE-2011-3156 Data HP Injection LogClientInstallation Protector SQL
Release Date
01/07/2013
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3336
False Positive
Unknown
Vendors

Hp

CVSS Score

10.0

Found a potential security threat?