CVE Database
/

CVE-2007-5289

Back to search

CVE-2007-5289

Published: Feb 24, 2009

Modified: Aug 7, 2024

PUBLISHED

Description

HP Mercury Quality Center (QC) 9.2 and earlier, and possibly TestDirector, relies on cached client-side scripts to implement "workflow" and decisions about the "capability" of a user, which allows remote attackers to execute arbitrary code via crafted use of the Open Test Architecture (OTA) API, as demonstrated by modifying (1) common.tds, (2) defects.tds, (3) manrun.tds, (4) req.tds, (5) testlab.tds, or (6) testplan.tds in %tmp%\TD_80, and then setting the file's properties to read-only.

VendorProductVersions

n/a

n/a

affected
n/a

References

34046
third-party-advisory
x_refsource_SECUNIA
20090223 HP Quality Center vulnerability
mailing-list
x_refsource_BUGTRAQ
33854
vdb-entry
x_refsource_BID
34015
third-party-advisory
x_refsource_SECUNIA
VU#898865
third-party-advisory
x_refsource_CERT-VN
20090224 Re: HP Quality Center vulnerability
mailing-list
x_refsource_BUGTRAQ

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now