VulnerabilityModified
CVE-2009-3693
Directory traversal vulnerability in the Persits.XUpload.2 ActiveX control (XUpload.ocx) in HP LoadRunner 9.5 allows remote attackers to create arbitrary files via \..
HIGH 9.3EPSS 41.6%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 41.6%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
Directory traversal vulnerability in the Persits.XUpload.2 ActiveX control (XUpload.ocx) in HP LoadRunner 9.5 allows remote attackers to create arbitrary files via \.. (backwards slash dot dot) sequences in the third argument to the MakeHttpRequest method.
- CVSS 2.0
- 9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 41.58% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- persits/xupload · hp/loadrunner
- Source
- cve@mitre.org
References
- http://retrogod.altervista.org/9sg_hp_loadrunner.htmlExploit
- http://secunia.com/advisories/36898Vendor Advisory
- http://retrogod.altervista.org/9sg_hp_loadrunner.htmlExploit
- http://secunia.com/advisories/36898Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.