Monday, April 28, 2008

Insecure Methods in HP Update Software

Execute code remotely is possible using methods ExecuteAsync and Execute :-)
If a user visits the malicious page the attacker can execute code.
Coded by callAX

http://www.milw0rm.com/exploits/5511

------------------------

According to Secunia, HP has addressed the vulnerabilities in 4.000.010.008 (see HP advisory for details).

No comments:

Post a Comment