The APISiteScopeImpl SOAP service in HP SiteScope 10.1x and 11.x before 11.22 allows remote attackers to bypass authentication and execute arbitrary code via a direct request to the issueSiebelCmd method, aka ZDI-CAN-1765.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Sitescope | Hp | 10.11 (including) | 10.11 (including) |
Sitescope | Hp | 10.13 (including) | 10.13 (including) |
Sitescope | Hp | 11.01 (including) | 11.01 (including) |
Sitescope | Hp | 11.1 (including) | 11.1 (including) |
Sitescope | Hp | 11.10 (including) | 11.10 (including) |
Sitescope | Hp | 11.11 (including) | 11.11 (including) |
Sitescope | Hp | 11.12 (including) | 11.12 (including) |
Sitescope | Hp | 11.20 (including) | 11.20 (including) |
Sitescope | Hp | 11.21 (including) | 11.21 (including) |