CVE-2014-2610
Summary
| CVE | CVE-2014-2610 |
|---|---|
| State | PUBLISHED |
| Assigner | hp |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-06-19 10:50:04 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | Directory traversal vulnerability in the Content Acceleration Pack (CAP) web application in HP Executive Scorecard 9.40 and 9.41 allows remote authenticated users to execute arbitrary code by uploading an executable file, aka ZDI-CAN-2117. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
HighAuthentication
SingleConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:H/Au:S/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Hp | Executive Scorecard | 9.40 | All | All | All |
| Application | Hp | Executive Scorecard | 9.41 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| HP IT Executive Scorecard Bugs Let Remote Users Traverse the Directory and Execute Arbitrary Code - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| Security Advisory SA59363 - HP IT Executive Scorecard Multiple Vulnerabilities - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| h20564.www2.hp.com/portal/site/hpsc/public/kb/docDisplay | af854a3a-2127-422b-91ae-364da2661108 | h20564.www2.hp.com | Vendor Advisory |
| HP Executive Scorecard Multiple Unspecified Remote Code Execution Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Zero Day Initiative | af854a3a-2127-422b-91ae-364da2661108 | zerodayinitiative.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.