blogs.zdnet.com
http://blogs.zdnet.com/security?p=768 CVE-2007-6506
HP Software Update Client 3.0.8.4 - Multiple Vulnerabilities
Record summary
CVE-2007-6506 has a selected CVSS score of 9.3; EIP currently links 1 catalogued exploit.
Description
The HPRulesEngine.ContentCollection.1 ActiveX Control in RulesEngine.dll for HP Software Update 4.000.005.007 and earlier, including 3.0.8.4, allows remote attackers to (1) overwrite and corrupt arbitrary files via arguments to the SaveToFile method, and possibly (2) access arbitrary files via the LoadDataFromFile method.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBHP Software Update Client 3.0.8.4 - Multiple VulnerabilitiesExploitDB exploitby porkythepigNot analyzed1 file
References
Showing 12 of 13computerworld.com
http://computerworld.com/action/article.do?command=viewArticleBasic&articleId=9053818 it.slashdot.org
http://it.slashdot.org/it/07/12/20/2327242.shtml 28177Third-party advisory
http://secunia.com/advisories/28177 anspi.pl
http://www.anspi.pl/~porkythepig/hp-issue/wyfukanyszynszyl.txt HPSBGN2301Vendor advisory
http://www.securityfocus.com/archive/1/485451/100/0/threaded HPSBGN02301Vendor advisory
http://www.securityfocus.com/archive/1/485734/100/0/threaded 26950vdb entry
http://www.securityfocus.com/bid/26950 1019133vdb entry
http://www.securitytracker.com/id?1019133 ADV-2007-4271vdb entry
http://www.vupen.com/english/advisories/2007/4271 hpsoftware-rulesengine-file-overwrite(39153)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/39153 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2007-6506