Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2007-6331

Опубликовано: 13 дек. 2007
Источник: nvd
CVSS2: 9.3
EPSS Низкий

Описание

Absolute path traversal vulnerability in the HPInfoDLL.HPInfo.1 ActiveX control in HPInfoDLL.dll 1.0, as shipped with HP Info Center (hpinfocenter.exe) 1.0.1.1 in HP Quick Launch Button (QLBCTRL.exe, aka QLB) 6.3 and earlier allows remote attackers to execute arbitrary programs via the first argument to the LaunchApp method. NOTE: only a user-assisted attack is possible on Windows Vista.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:hp:info_center:1.0.1.1:*:*:*:*:*:*:*
cpe:2.3:a:hp:quick_launch_button:*:*:*:*:*:*:*:*
Версия до 6.3 (включая)

EPSS

Процентиль: 91%
0.06207
Низкий

9.3 Critical

CVSS2

Дефекты

CWE-22

Связанные уязвимости

github
почти 4 года назад

Absolute path traversal vulnerability in the HPInfoDLL.HPInfo.1 ActiveX control in HPInfoDLL.dll 1.0, as shipped with HP Info Center (hpinfocenter.exe) 1.0.1.1 in HP Quick Launch Button (QLBCTRL.exe, aka QLB) 6.3 and earlier allows remote attackers to execute arbitrary programs via the first argument to the LaunchApp method. NOTE: only a user-assisted attack is possible on Windows Vista.

EPSS

Процентиль: 91%
0.06207
Низкий

9.3 Critical

CVSS2

Дефекты

CWE-22