PT-2007-7340 · Hewlett Packard · Hp Software Update+1

Porkythepig

·

Published

2007-12-20

·

Updated

2018-10-15

·

CVE-2007-6506

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions HP Software Update versions 3.0.8.4 through 4.000.005.007
Description The issue allows remote attackers to overwrite and corrupt arbitrary files via arguments to the SaveToFile method, and possibly access arbitrary files via the LoadDataFromFile method.
Recommendations For HP Software Update versions 3.0.8.4 through 4.000.005.007, consider disabling the SaveToFile and LoadDataFromFile methods until a patch is available. Restrict access to the RulesEngine.dll to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-6506

Affected Products

Hp Software Update
Rulesengine.Dll