This module exploits a buffer overflow vulnerability in the ovalarmsrv module of the HP OpenView Network Node Manager application. The exploit triggers a stack-based buffer overflow by sending a specially crafted packet to port 2954/TCP of the vulnerable system and installs an agent if successful. This module works disabling DEP on Windows 2003 Enterprise Edition sp2 in the context of the vulnerable application.
This module exploits a stack-based buffer overflow in the snmpviewer.exe CGI application, a component of HP OpenView Network Node Manager, by sending an HTTP request with an invalid value for the act and app parameters. The agent installed by this exploit will run as "IUSR" user. Authentication is not required for this exploit to work.