CVE-2007-6331
N/A
N/A
Summary
Absolute path traversal vulnerability in the HPInfoDLL.HPInfo.1 ActiveX control in HPInfoDLL.dll 1.0, as shipped with HP Info Center (hpinfocenter.exe) 1.0.1.1 in HP Quick Launch Button (QLBCTRL.exe, aka QLB) 6.3 and earlier allows remote attackers to execute arbitrary programs via the first argument to the LaunchApp method. NOTE: only a user-assisted attack is possible on Windows Vista.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | n/a | n/a | affected |
Weaknesses
- n/a
ADP Enrichment
CVE Program Container
Additional References
- http://www.securityfocus.com/bid/26823
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01300486
- https://www.exploit-db.com/exploits/4720
- http://www.vupen.com/english/advisories/2007/4192
- http://securitytracker.com/id?1019086
- http://secunia.com/advisories/28055
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01300486
- https://exchange.xforce.ibmcloud.com/vulnerabilities/38991
- http://www.securityfocus.com/archive/1/484880/100/100/threaded
- http://www.anspi.pl/~porkythepig/hp-issue/kilokieubasy.txt
References
- http://www.securityfocus.com/bid/26823
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01300486
- https://www.exploit-db.com/exploits/4720
- http://www.vupen.com/english/advisories/2007/4192
- http://securitytracker.com/id?1019086
- http://secunia.com/advisories/28055
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01300486
- https://exchange.xforce.ibmcloud.com/vulnerabilities/38991
- http://www.securityfocus.com/archive/1/484880/100/100/threaded
- http://www.anspi.pl/~porkythepig/hp-issue/kilokieubasy.txt
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.