peter bassill · operator
$ cve CVE-2011-4166 JSON

CVE-2011-4166 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 58.3% (pctl 99)

Patch early

A public exploit exists.

Description

Directory traversal vulnerability in the MPAUploader.Uploader.1.UploadFiles method in HP Managed Printing Administration before 2.6.4 allows remote attackers to create arbitrary files via crafted form data.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS58.34% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-22
On CISA KEVno
Public exploityes
Published2011-12-27
Last modified2026-06-16

Affected (1)

VendorProduct
hpmanaged printing administration

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD