Search:     Advanced search
server monitoring

HP Instant Support HPISDataManager.dll ActiveX Control < 1.0.0.24 Vulnerabilities

Article ID: 33095
Last updated: 27 Jan, 2009
Views: 391
Posted: 22 Jan, 2009
by: Tech Pubs S.
Updated: 27 Jan, 2009
by: Tech Pubs S.

HP Instant Support HPISDataManager.dll ActiveX Control < 1.0.0.24 Vulnerabilities

This script is Copyright (C) 2008 Tenable Network Security, Inc.

FamilyWindows
Plugin ID33095
Bugtraq ID29529
29530
29531
29532
29533
29534
29535
29536
CVE IDCVE-2007-5604
CVE-2007-5605
CVE-2007-5606
CVE-2007-5607
CVE-2007-5608
CVE-2007-5610
CVE-2008-0952
CVE-2008-0953

Description:

Synopsis :

The remote Windows host has several ActiveX controls that are affected
by multiple vulnerabilities.

Description :

The remote host contains several ActiveX controls in HP Instant
Support HPISDataManager.dll, a web-based diagnostic tool from
Hewlett-Packard.

The version of the controls installed on the remote host reportedly
are affected by several issues. If an attacker can trick a user on
the affected host into viewing a specially-crafted HTML document, he
may be able to use this method to execute arbitrary code by means of
buffer overflows or to execute delete, download, and write to
arbitrary files on the affected system, all subject to the users
privileges.

See also :

http://www.csis.dk/dk/forside/CSIS-RI-0003.pdf
http://archives.neohapsis.com/archives/bugtraq/2008-06/0031.html
http://archives.neohapsis.com/archives/bugtraq/2008-06/0028.html

Solution :

Upgrade to HP Instant Support version 1.0.0.24 or later.

Risk factor :

High / CVSS Base Score : 9.3
(CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
This article was:   Helpful | Not Helpful
Prev   Next
3ivx MPEG-4 < 5.0.2 Buffer Overflow     Microsoft Dynamics GP < 10.0 Multiple Vulnerabilities