CVE-2007-6331
high · 9.3Absolute path traversal vulnerability in the HPInfoDLL.HPInfo.1 ActiveX control in HPInfoDLL.dll 1.0, as shipped with HP Info Center (hpinfocenter.exe) 1.0.1.1 in HP Quick Launch Button (QLBCTRL.exe, aka QLB) 6.3 and earlier allows remote attackers to execute arbitrary programs via the first argument to the LaunchApp method. NOTE: only a user-assisted attack is possible on Windows Vista.
9.3
CVSS
30.1%
EPSS (exploit prob.)
98th
EPSS percentile
2007-12-13
Published
AV:N/AC:M/Au:N/C:C/I:C/A:C
Weaknesses
CWE-22
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| hp | info_center | 1.0.1.1 |
| hp | quick_launch_button | <= 6.3 |
Check a specific version with /api/v1/cve/match.
References
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01300486
- http://secunia.com/advisories/28055
- http://securitytracker.com/id?1019086
- http://www.anspi.pl/~porkythepig/hp-issue/kilokieubasy.txt
- http://www.securityfocus.com/archive/1/484880/100/100/threaded
- http://www.securityfocus.com/bid/26823
- http://www.vupen.com/english/advisories/2007/4192
- https://exchange.xforce.ibmcloud.com/vulnerabilities/38991
- https://www.exploit-db.com/exploits/4720
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01300486
- http://secunia.com/advisories/28055
- http://securitytracker.com/id?1019086
- http://www.anspi.pl/~porkythepig/hp-issue/kilokieubasy.txt
- http://www.securityfocus.com/archive/1/484880/100/100/threaded
- http://www.securityfocus.com/bid/26823
- http://www.vupen.com/english/advisories/2007/4192
- https://exchange.xforce.ibmcloud.com/vulnerabilities/38991
- https://www.exploit-db.com/exploits/4720
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2007-6331