CVE-2013-6221

Directory traversal vulnerability in CommunicationServlet in HP Service Virtualization 3.x before 3.50.1, when the AutoPass license server is enabled, allows remote attackers to create arbitrary files and consequently execute arbitrary code via unspecified vectors, aka ZDI-CAN-2031.
Configurations

Configuration 1 (hide)

cpe:2.3:a:hp:service_virtualization:3.0:*:*:*:*:*:*:*

History

21 Nov 2024, 01:58

Type Values Removed Values Added
References () http://packetstormsecurity.com/files/127247/HP-AutoPass-License-Server-File-Upload.html - () http://packetstormsecurity.com/files/127247/HP-AutoPass-License-Server-File-Upload.html -
References () http://www.exploit-db.com/exploits/33891 - () http://www.exploit-db.com/exploits/33891 -
References () http://www.osvdb.org/107943 - () http://www.osvdb.org/107943 -
References () http://www.securitytracker.com/id/1030385 - () http://www.securitytracker.com/id/1030385 -
References () http://zerodayinitiative.com/advisories/ZDI-14-195/ - () http://zerodayinitiative.com/advisories/ZDI-14-195/ -
References () https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/http/hp_autopass_license_traversal.rb - () https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/http/hp_autopass_license_traversal.rb -
References () https://h20564.www2.hp.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04333125 - Vendor Advisory () https://h20564.www2.hp.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04333125 - Vendor Advisory

Information

Published : 2014-06-18 16:55

Updated : 2024-11-21 01:58


NVD link : CVE-2013-6221

Mitre link : CVE-2013-6221

CVE.ORG link : CVE-2013-6221


JSON object : View

Products Affected

hp

  • service_virtualization
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')