CVE-2007-6513
HP eSupportDiagnostics ActiveX control <1.0.11.0 - Info Disclosure
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-6513. PoCs published by Elazar Broad.
AI-analyzed exploit summary This exploit leverages the HP eSupportDiagnostics ActiveX control to disclose arbitrary file contents and registry values via the ReadTextFile and ReadValue methods. The PoC is a simple HTML page that triggers the vulnerability when loaded.
Description
HP eSupportDiagnostics ActiveX control (hpediag.dll) 1.0.11.0 exports dangerous methods, which allows remote attackers to (1) read arbitrary files via the ReadTextFile method, or (2) read arbitrary registry values via the ReadValue method.
Exploits (1)
This exploit leverages the HP eSupportDiagnostics ActiveX control to disclose arbitrary file contents and registry values via the ReadTextFile and ReadValue methods. The PoC is a simple HTML page that triggers the vulnerability when loaded.