module
HP OpenView Performance Insight Server Backdoor Account Code Execution
Disclosed | Created |
---|---|
2011-01-31 | 2018-05-30 |
Disclosed
2011-01-31
Created
2018-05-30
Description
This module exploits a hidden account in the com.trinagy.security.XMLUserManager Java
class. When using this account, an attacker can abuse the
com.trinagy.servlet.HelpManagerServlet class and write arbitrary files to the system
allowing the execution of arbitrary code.
NOTE: This module has only been tested against HP OpenView Performance Insight Server 5.41.0
class. When using this account, an attacker can abuse the
com.trinagy.servlet.HelpManagerServlet class and write arbitrary files to the system
allowing the execution of arbitrary code.
NOTE: This module has only been tested against HP OpenView Performance Insight Server 5.41.0
Author
MC mc@metasploit.com
Platform
Windows
References
Module Options
To display the available options, load the module within the Metasploit console and run the commands ‘show options’ or ‘show advanced’:

NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.