Lucene search

K
zdiMike Arnold (Bruk0ut)ZDI-14-209
HistoryJun 18, 2014 - 12:00 a.m.

Hewlett-Packard IT Executive Scorecard CAP File Upload Directory Traversal Remote Code Execution Vulnerability

2014-06-1800:00:00
Mike Arnold (Bruk0ut)
www.zerodayinitiative.com
15

EPSS

0.034

Percentile

91.5%

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Hewlett-Packard IT Executive Scorecard. Authentication is required to exploit this vulnerability. The specific flaw exists within the Content Acceleration Pack web application code. A file upload directory traversal vulnerability can be leveraged to execute code under the context of the SYSTEM user.

EPSS

0.034

Percentile

91.5%