7.8
CVSSv2

CVE-2013-3574

Published: 14/06/2013 Updated: 14/06/2013
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
VMScore: 785
Vector: AV:N/AC:L/Au:N/C:N/I:C/A:N

Vulnerability Summary

Absolute path traversal vulnerability in hpdiags/frontend2/commands/saveCompareConfig.php in HP Insight Diagnostics 9.4.0.4710 allows remote malicious users to write data to arbitrary files via a full pathname in the argument to the devicePath (aka mount) parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

hp insight diagnostics 9.4.0.4710

Exploits

source: wwwsecurityfocuscom/bid/60447/info HP Insight Diagnostics is prone to a remote code-injection vulnerability An attacker can exploit this vulnerability to inject and execute arbitrary code within the context of the affected application HP Insight Diagnostics 9404710 is vulnerable; other versions may also be affected https: ...