HP LoadRunner XUpload.ocx ActiveX Control 'MakeHttpRequest()' Arbitrary File Download Vulnerability
BID:36550
Info
HP LoadRunner XUpload.ocx ActiveX Control 'MakeHttpRequest()' Arbitrary File Download Vulnerability
| Bugtraq ID: | 36550 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 30 2009 12:00AM |
| Updated: | Sep 30 2009 04:50PM |
| Credit: | Nine:Situations:Group::Pyrokinesis |
| Vulnerable: |
HP Mercury LoadRunner Agent 9.5 |
| Not Vulnerable: | |
Discussion
HP LoadRunner XUpload.ocx ActiveX Control 'MakeHttpRequest()' Arbitrary File Download Vulnerability
HP LoadRunner Persits.XUpload.2 ActiveX control is prone to a vulnerability that can allow attackers to download malicious files and save them to arbitrary locations on an affected computer.
Attackers may exploit this issue to execute malicious files within the context of the affected application that uses the affected control (typically Internet Explorer). Other attacks are also possible.
LoadRunner 9.5 is vulnerable; other versions may also be affected.
HP LoadRunner Persits.XUpload.2 ActiveX control is prone to a vulnerability that can allow attackers to download malicious files and save them to arbitrary locations on an affected computer.
Attackers may exploit this issue to execute malicious files within the context of the affected application that uses the affected control (typically Internet Explorer). Other attacks are also possible.
LoadRunner 9.5 is vulnerable; other versions may also be affected.
Exploit / POC
HP LoadRunner XUpload.ocx ActiveX Control 'MakeHttpRequest()' Arbitrary File Download Vulnerability
An exploit is available:
An exploit is available:
Solution / Fix
HP LoadRunner XUpload.ocx ActiveX Control 'MakeHttpRequest()' Arbitrary File Download Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
HP LoadRunner XUpload.ocx ActiveX Control 'MakeHttpRequest()' Arbitrary File Download Vulnerability
References:
References: