Computer Security
[EN] securityvulns.ru
no-pyccku



CVECVE-2007-6331
StatusCandidate
DescriptionAbsolute path traversal vulnerability in the HPInfoDLL.HPInfo.1 ActiveX control in HPInfoDLL.dll 1.0, as shipped with HP Info Center (hpinfocenter.exe) 1.0.1.1 in HP Quick Launch Button (QLBCTRL.exe, aka QLB) 6.3 and earlier allows remote attackers to execute arbitrary programs via the first argument to the LaunchApp method.  NOTE: only a user-assisted attack is possible on Windows Vista.
PhaseAssigned (13.12.2007)
SecurityVulns:HP Info Center ActiveX code execution
NVD:http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-6331
ReferencesBID : 26823
 BUGTRAQ : 20071211 HP notebooks remote code execution vulnerability (multiple series)
 FRSIRT : ADV-2007-4192
 HP : HPSBGN02298
 HP : SSRT071502
 MILW0RM : 4720
 MISC : http://www.anspi.pl/~porkythepig/hp-issue/kilokieu...
 SECTRACK : 1019086
 SECUNIA : 28055
 XF : hpinfo-hpinfo-command-execution(38991)

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
 



Рейтинг@Mail.ru