CVE-2008-0068 EXPLOIT
5.0
MEDIUM · CVSS 2.0 · EPSS 5.1% (pctl 92)
Patch early
A public exploit exists.
Description
Directory traversal vulnerability in OpenView5.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to read arbitrary files via directory traversal sequences in the Action parameter.
Scoring
| CVSS | 5.0 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
| EPSS | 5.09% — more likely to be exploited than 92% of all CVEs |
| Weakness | CWE-22 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2008-04-16 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| hp | openview network node manager |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | HP OpenView Network Node Manager (OV NNM) 7.x - 'OpenView5.exe?Action' Traversal Arbitrary File Access | 2008-04-11 |
References
- http://aluigi.altervista.org/adv/closedviewx-adv.txt
- http://marc.info/?l=bugtraq&m=121553649611253&w=2
- http://secunia.com/advisories/29796
- http://secunia.com/secunia_research/2008-4/advisory/
- http://securityreason.com/securityalert/3814
- http://www.osvdb.org/44359
- http://www.securityfocus.com/archive/1/490771
- http://www.securityfocus.com/archive/1/490834/100/0/threaded
- http://www.securityfocus.com/bid/28745
- http://www.securitytracker.com/id?1019838
- http://www.securitytracker.com/id?1019839
- http://www.vupen.com/english/advisories/2008/1214/references
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41790
- http://aluigi.altervista.org/adv/closedviewx-adv.txt
- http://marc.info/?l=bugtraq&m=121553649611253&w=2
- http://secunia.com/advisories/29796
- http://secunia.com/secunia_research/2008-4/advisory/
- http://securityreason.com/securityalert/3814
- http://www.osvdb.org/44359
- http://www.securityfocus.com/archive/1/490771
→ the Explorer · watch your stack · NVD