9.3
CVSSv2

CVE-2007-6331

Published: 13/12/2007 Updated: 15/10/2018
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 935
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Absolute path traversal vulnerability in the HPInfoDLL.HPInfo.1 ActiveX control in HPInfoDLL.dll 1.0, as shipped with HP Info Center (hpinfocenter.exe) 1.0.1.1 in HP Quick Launch Button (QLBCTRL.exe, aka QLB) 6.3 and previous versions allows remote malicious users to execute arbitrary programs via the first argument to the LaunchApp method. NOTE: only a user-assisted attack is possible on Windows Vista.

Vulnerable Product Search on Vulmon Subscribe to Product

hp quick launch button

hp info center 1.0.1.1

Exploits

<!- Advisory: Multiple Hewlett-Packard notebook series are prone to a remote code execution attack The manufacturer's preinstalled software contains a critical flaw within the software built to support one-touch button quick feature access Overview: ///////// Software called "HP Info Center" is shipped with almost every HP laptop model for ...