CVE-2013-6221

HP Service Virtualization - Path Traversal

Title source: rule

Description

Directory traversal vulnerability in CommunicationServlet in HP Service Virtualization 3.x before 3.50.1, when the AutoPass license server is enabled, allows remote attackers to create arbitrary files and consequently execute arbitrary code via unspecified vectors, aka ZDI-CAN-2031.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotejava
https://www.exploit-db.com/exploits/33891
metasploit WORKING POC GREAT
rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/http/hp_autopass_license_traversal.rb

Scores

EPSS 0.8414
EPSS Percentile 99.3%

Details

CWE
CWE-22
Status published
Products (1)
hp/service_virtualization 3.0
Published Jun 18, 2014
Tracked Since Feb 18, 2026