Get a Pentest and security assessment of your IT network.

Advisories

Zero Day Initiative Advisory 07-020

Vulnerabilities allow attackers to execute arbitrary code on vulnerable installations of BMC Performance Manager. User interaction is not required to exploit this vulnerability. The specific flaw exists in the PatrolAgent.exe listening on TCP port 3181. The service allows remote attackers to modify configuration files without authentication. This can be exploited by an attacker by modifying parameters in SNMP communities definitions. By modifying the masterAgentName and masterAgentStartLine parameters, an attacker can execute arbitrary code.

 

You can download this advisory from the following link: https://packetstormsecurity.com/files/download/56075/ZDI-07-020.txt

Source: https://packetstormsecurity.com/files/56075/Zero-Day-Initiative-Advisory-07-020.html

Related posts
Advisories

LynX-adv4_SignatureDB.txt

Advisories

Secunia Security Advisory 16497

Advisories

Secunia Security Advisory 19451

Advisories

Debian Linux Security Advisory 1187-1