CVE-2009-3693
Published Oct 13, 2009
Last updated 15 years ago
Overview
- Description
- Directory traversal vulnerability in the Persits.XUpload.2 ActiveX control (XUpload.ocx) in HP LoadRunner 9.5 allows remote attackers to create arbitrary files via \.. (backwards slash dot dot) sequences in the third argument to the MakeHttpRequest method.
- Source
- cve@mitre.org
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 9.3
- Impact score
- 10
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:C/I:C/A:C
Weaknesses
- nvd@nist.gov
- CWE-22
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:persits:xupload:2.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7F151EAF-714D-4E3E-BBCF-26D416865D4B" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:hp:loadrunner:9.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "11C140E6-D09F-4B81-A1E0-F7661855FC5D" } ], "operator": "OR" } ], "operator": "AND" } ]