SSRT071502Vendor advisory
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01300486 CVE-2007-6331
HP Compaq Notebooks - ActiveX Remote Code Execution
Record summary
CVE-2007-6331 has a selected CVSS score of 9.3; EIP currently links 1 catalogued exploit.
Description
Absolute path traversal vulnerability in the HPInfoDLL.HPInfo.1 ActiveX control in HPInfoDLL.dll 1.0, as shipped with HP Info Center (hpinfocenter.exe) 1.0.1.1 in HP Quick Launch Button (QLBCTRL.exe, aka QLB) 6.3 and earlier allows remote attackers to execute arbitrary programs via the first argument to the LaunchApp method. NOTE: only a user-assisted attack is possible on Windows Vista.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBHP Compaq Notebooks - ActiveX Remote Code ExecutionExploitDB exploitby porkythepigNot analyzed1 file
References
1028055Third-party advisory
http://secunia.com/advisories/28055 1019086vdb entry
http://securitytracker.com/id?1019086 anspi.pl
http://www.anspi.pl/~porkythepig/hp-issue/kilokieubasy.txt 20071211 HP notebooks remote code execution vulnerability (multiple series)mailing list
http://www.securityfocus.com/archive/1/484880/100/100/threaded 26823vdb entry
http://www.securityfocus.com/bid/26823 ADV-2007-4192vdb entry
http://www.vupen.com/english/advisories/2007/4192 hpinfo-hpinfo-command-execution(38991)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/38991 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2007-6331 4720exploit
https://www.exploit-db.com/exploits/4720