HP Application Lifecycle Management 'XGO.ocx' Multiple Remote Code Execution Vulnerabilities
BID:55272
Info
HP Application Lifecycle Management 'XGO.ocx' Multiple Remote Code Execution Vulnerabilities
| Bugtraq ID: | 55272 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 29 2012 12:00AM |
| Updated: | Mar 19 2015 08:05AM |
| Credit: | Andrea Micalizzi |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
HP Application Lifecycle Management 'XGO.ocx' Multiple Remote Code Execution Vulnerabilities
HP Application Lifecycle Management is prone to multiple remote code-execution vulnerabilities.
Successfully exploiting these issues allows remote attackers to execute arbitrary code in the context of the process (typically Internet Explorer) using the ActiveX control. Failed exploit attempts likely result in denial-of-service conditions.
HP Application Lifecycle Management is prone to multiple remote code-execution vulnerabilities.
Successfully exploiting these issues allows remote attackers to execute arbitrary code in the context of the process (typically Internet Explorer) using the ActiveX control. Failed exploit attempts likely result in denial-of-service conditions.
Exploit / POC
HP Application Lifecycle Management 'XGO.ocx' Multiple Remote Code Execution Vulnerabilities
The following Metasploit module is available:
The following Metasploit module is available:
Solution / Fix
HP Application Lifecycle Management 'XGO.ocx' Multiple Remote Code Execution Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
HP Application Lifecycle Management 'XGO.ocx' Multiple Remote Code Execution Vulnerabilities
References:
References: