Unrated severityNVD Advisory· Published Jan 20, 2010· Updated Apr 29, 2026
CVE-2009-4000
CVE-2009-4000
Description
Directory traversal vulnerability in goform/formExportDataLogs in HP Power Manager before 4.2.10 allows remote attackers to overwrite arbitrary files, and execute arbitrary code, via directory traversal sequences in the fileName parameter.
Affected products
5cpe:2.3:a:hp:power_manager:*:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:hp:power_manager:*:*:*:*:*:*:*:*range: <=4.2.9
- cpe:2.3:a:hp:power_manager:4.2.5:*:*:*:*:*:*:*
- cpe:2.3:a:hp:power_manager:4.2.6:*:*:*:*:*:*:*
- cpe:2.3:a:hp:power_manager:4.2.7:*:*:*:*:*:*:*
- cpe:2.3:a:hp:power_manager:4.2.8:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- marc.infonvdVendor Advisory
- secunia.com/advisories/37280nvdVendor Advisory
- secunia.com/secunia_research/2009-48/nvdVendor Advisory
- securitytracker.com/idnvd
- www.securityfocus.com/bid/37873nvd
News mentions
0No linked articles in our index yet.