HP.Multiple.Products.LogClientInstallation.SQL.Injection

description-logoDescription

This indicates an attack attempt to exploit a SQL Injection vulnerability in HP Data Protector Notebook Extension and HP Data Protector for Personal Computers.
The vulnerability is due to insufficient sanitizing of user supplied inputs in the application. As a result, a remote attacker can send a crafted query to execute SQL commands on a vulnerable server.

affected-products-logoAffected Products

HP Data Protector for Personal Computers 7.0 and earlier versions
HP Data Protector Notebook Extension 6.20 and earlier versions

Impact logoImpact

System Compromise: Remote attackers can execute arbitrary SQL queries within the context of the application.

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)