Exploitation Summary
EIP tracks 1 public exploit for CVE-2007-1882. PoCs published by Isma Khan.
AI-analyzed exploit summary This Perl script exploits an authentication bypass in HP Mercury Quality Center (CVE-2007-1882) to execute arbitrary SQL queries via the 'RunQuery' command. It demonstrates blind SQL injection by updating user data without proper authorization.
Description
qcbin/servlet/tdservlet/TDAPI_GeneralWebTreatment in HP Mercury Quality Center 9.0 build 9.1.0.4352 allows remote authenticated users to execute arbitrary SQL commands via the RunQuery method.
Exploits (1)
This Perl script exploits an authentication bypass in HP Mercury Quality Center (CVE-2007-1882) to execute arbitrary SQL queries via the 'RunQuery' command. It demonstrates blind SQL injection by updating user data without proper authorization.