{"api_version":"1","generated_at":"2026-07-23T13:33:26+00:00","cve":"CVE-2007-6506","urls":{"html":"https://cve.report/CVE-2007-6506","api":"https://cve.report/api/cve/CVE-2007-6506.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2007-6506","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2007-6506"},"summary":{"title":"CVE-2007-6506","description":"The HPRulesEngine.ContentCollection.1 ActiveX Control in RulesEngine.dll for HP Software Update 4.000.005.007 and earlier, including 3.0.8.4, allows remote attackers to (1) overwrite and corrupt arbitrary files via arguments to the SaveToFile method, and possibly (2) access arbitrary files via the LoadDataFromFile method.","state":"PUBLISHED","assigner":"mitre","published_at":"2007-12-20 23:46:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"9.3","severity":"","vector":"AV:N/AC:M/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://computerworld.com/action/article.do?command=viewArticleBasic&articleId=9053818","name":"http://computerworld.com/action/article.do?command=viewArticleBasic&articleId=9053818","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"'Bricking' bug threatens most HP, Compaq laptops","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/26950","name":"http://www.securityfocus.com/bid/26950","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"HP Software Update 'RulesEngine.dll' ActiveX Control Multiple File Overwrite Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://secunia.com/advisories/28177","name":"http://secunia.com/advisories/28177","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"HP Software Update ContentCollection Class ActiveX Control Insecure Method - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id?1019133","name":"http://www.securitytracker.com/id?1019133","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityTracker.com Archives - HP Software Update ActiveX Control Has Unsafe Method That Lets Remote Users Damage Files or Execute Arbitrary Code","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.exploit-db.com/exploits/4757","name":"https://www.exploit-db.com/exploits/4757","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"HP Software Update Client 3.0.8.4 - Multiple Vulnerabilities - Windows dos Exploit","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2007/4271","name":"http://www.vupen.com/english/advisories/2007/4271","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://it.slashdot.org/it/07/12/20/2327242.shtml","name":"http://it.slashdot.org/it/07/12/20/2327242.shtml","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Exploit Found to Brick Most HP and Compaq Laptops - Slashdot","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/485734/100/0/threaded","name":"http://www.securityfocus.com/archive/1/485734/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/485451/100/0/threaded","name":"http://www.securityfocus.com/archive/1/485451/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.anspi.pl/~porkythepig/hp-issue/wyfukanyszynszyl.txt","name":"http://www.anspi.pl/~porkythepig/hp-issue/wyfukanyszynszyl.txt","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"text/plain","httpstatus":"-1","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/39153","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/39153","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://blogs.zdnet.com/security/?p=768","name":"http://blogs.zdnet.com/security/?p=768","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"» HP laptops: Another zero-day vulnerability found | Zero Day | ZDNet.com","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2007-6506","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2007-6506","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2007","cve_id":"6506","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"hp","cpe5":"software_update","cpe6":"3.0.8.4","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"6506","vulnerable":"1","versionEndIncluding":"4.000.005.007","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"hp","cpe5":"software_update","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T16:11:06.001Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"1019133","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1019133"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://blogs.zdnet.com/security/?p=768"},{"name":"HPSBGN2301","tags":["vendor-advisory","x_refsource_HP","x_transferred"],"url":"http://www.securityfocus.com/archive/1/485451/100/0/threaded"},{"name":"28177","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/28177"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://computerworld.com/action/article.do?command=viewArticleBasic&articleId=9053818"},{"name":"4757","tags":["exploit","x_refsource_EXPLOIT-DB","x_transferred"],"url":"https://www.exploit-db.com/exploits/4757"},{"name":"hpsoftware-rulesengine-file-overwrite(39153)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/39153"},{"name":"ADV-2007-4271","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2007/4271"},{"name":"26950","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/26950"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.anspi.pl/~porkythepig/hp-issue/wyfukanyszynszyl.txt"},{"name":"SSRT071508","tags":["vendor-advisory","x_refsource_HP","x_transferred"],"url":"http://www.securityfocus.com/archive/1/485451/100/0/threaded"},{"name":"HPSBGN02301","tags":["vendor-advisory","x_refsource_HP","x_transferred"],"url":"http://www.securityfocus.com/archive/1/485734/100/0/threaded"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://it.slashdot.org/it/07/12/20/2327242.shtml"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2007-12-20T00:00:00.000Z","descriptions":[{"lang":"en","value":"The HPRulesEngine.ContentCollection.1 ActiveX Control in RulesEngine.dll for HP Software Update 4.000.005.007 and earlier, including 3.0.8.4, allows remote attackers to (1) overwrite and corrupt arbitrary files via arguments to the SaveToFile method, and possibly (2) access arbitrary files via the LoadDataFromFile method."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-15T20:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"1019133","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1019133"},{"tags":["x_refsource_MISC"],"url":"http://blogs.zdnet.com/security/?p=768"},{"name":"HPSBGN2301","tags":["vendor-advisory","x_refsource_HP"],"url":"http://www.securityfocus.com/archive/1/485451/100/0/threaded"},{"name":"28177","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/28177"},{"tags":["x_refsource_MISC"],"url":"http://computerworld.com/action/article.do?command=viewArticleBasic&articleId=9053818"},{"name":"4757","tags":["exploit","x_refsource_EXPLOIT-DB"],"url":"https://www.exploit-db.com/exploits/4757"},{"name":"hpsoftware-rulesengine-file-overwrite(39153)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/39153"},{"name":"ADV-2007-4271","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2007/4271"},{"name":"26950","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/26950"},{"tags":["x_refsource_MISC"],"url":"http://www.anspi.pl/~porkythepig/hp-issue/wyfukanyszynszyl.txt"},{"name":"SSRT071508","tags":["vendor-advisory","x_refsource_HP"],"url":"http://www.securityfocus.com/archive/1/485451/100/0/threaded"},{"name":"HPSBGN02301","tags":["vendor-advisory","x_refsource_HP"],"url":"http://www.securityfocus.com/archive/1/485734/100/0/threaded"},{"tags":["x_refsource_MISC"],"url":"http://it.slashdot.org/it/07/12/20/2327242.shtml"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2007-6506","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The HPRulesEngine.ContentCollection.1 ActiveX Control in RulesEngine.dll for HP Software Update 4.000.005.007 and earlier, including 3.0.8.4, allows remote attackers to (1) overwrite and corrupt arbitrary files via arguments to the SaveToFile method, and possibly (2) access arbitrary files via the LoadDataFromFile method."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"1019133","refsource":"SECTRACK","url":"http://www.securitytracker.com/id?1019133"},{"name":"http://blogs.zdnet.com/security/?p=768","refsource":"MISC","url":"http://blogs.zdnet.com/security/?p=768"},{"name":"HPSBGN2301","refsource":"HP","url":"http://www.securityfocus.com/archive/1/485451/100/0/threaded"},{"name":"28177","refsource":"SECUNIA","url":"http://secunia.com/advisories/28177"},{"name":"http://computerworld.com/action/article.do?command=viewArticleBasic&articleId=9053818","refsource":"MISC","url":"http://computerworld.com/action/article.do?command=viewArticleBasic&articleId=9053818"},{"name":"4757","refsource":"EXPLOIT-DB","url":"https://www.exploit-db.com/exploits/4757"},{"name":"hpsoftware-rulesengine-file-overwrite(39153)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/39153"},{"name":"ADV-2007-4271","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2007/4271"},{"name":"26950","refsource":"BID","url":"http://www.securityfocus.com/bid/26950"},{"name":"http://www.anspi.pl/~porkythepig/hp-issue/wyfukanyszynszyl.txt","refsource":"MISC","url":"http://www.anspi.pl/~porkythepig/hp-issue/wyfukanyszynszyl.txt"},{"name":"SSRT071508","refsource":"HP","url":"http://www.securityfocus.com/archive/1/485451/100/0/threaded"},{"name":"HPSBGN02301","refsource":"HP","url":"http://www.securityfocus.com/archive/1/485734/100/0/threaded"},{"name":"http://it.slashdot.org/it/07/12/20/2327242.shtml","refsource":"MISC","url":"http://it.slashdot.org/it/07/12/20/2327242.shtml"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2007-6506","datePublished":"2007-12-20T23:00:00.000Z","dateReserved":"2007-12-20T00:00:00.000Z","dateUpdated":"2024-08-07T16:11:06.001Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2007-12-20 23:46:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":8.6,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:hp:software_update:*:*:*:*:*:*:*:*","versionEndIncluding":"4.000.005.007","matchCriteriaId":"A5442F10-8ABC-4DE8-A88E-0BA0D89FE759"},{"vulnerable":true,"criteria":"cpe:2.3:a:hp:software_update:3.0.8.4:*:*:*:*:*:*:*","matchCriteriaId":"3CBD25D9-490E-4740-B645-0859E00EA95B"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2007","CveId":"6506","Ordinal":"1","Title":"CVE-2007-6506","CVE":"CVE-2007-6506","Year":"2007"},"notes":[{"CveYear":"2007","CveId":"6506","Ordinal":"1","NoteData":"The HPRulesEngine.ContentCollection.1 ActiveX Control in RulesEngine.dll for HP Software Update 4.000.005.007 and earlier, including 3.0.8.4, allows remote attackers to (1) overwrite and corrupt arbitrary files via arguments to the SaveToFile method, and possibly (2) access arbitrary files via the LoadDataFromFile method.","Type":"Description","Title":"CVE-2007-6506"},{"CveYear":"2007","CveId":"6506","Ordinal":"2","NoteData":"2007-12-20","Type":"Other","Title":"Published"},{"CveYear":"2007","CveId":"6506","Ordinal":"3","NoteData":"2018-10-15","Type":"Other","Title":"Modified"}]}}}