CVE-2007-5608
Last modified
CVE-2007-5608 is a vulnerability of currently unknown severity. The DownloadFile function in the HPISDataManagerLib.Datamgr ActiveX control in HPISDataManager.dll in HP Instant Support before 1.0.0.24 allows remote attackers to force a download of an arbitrary file onto a client machine via a URL in the first argument and a destination filename in the second argument, a different vulnerability than CVE-2008-0952 and CVE-2008-0953.. EPSS estimates a 3.59% chance of exploitation in the next 30 days.
Description
The DownloadFile function in the HPISDataManagerLib.Datamgr ActiveX control in HPISDataManager.dll in HP Instant Support before 1.0.0.24 allows remote attackers to force a download of an arbitrary file onto a client machine via a URL in the first argument and a destination filename in the second argument, a different vulnerability than CVE-2008-0952 and CVE-2008-0953.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Hp | Instant Support | <= 1.0.0.23 |
References
- http://secunia.com/advisories/30516Vendor Advisory
- http://www.kb.cert.org/vuls/id/949587US Government Resource
- http://secunia.com/advisories/30516Vendor Advisory
- http://www.kb.cert.org/vuls/id/949587US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-5608?
How severe is CVE-2007-5608?
How do I fix CVE-2007-5608?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2007
- CVE-2007-5602Multiple stack-based buffer overflows in SwiftView Viewer be…
- CVE-2007-5603Stack-based buffer overflow in the SonicWall SSL-VPN NetExte…
- CVE-2007-5604Buffer overflow in the ExtractCab function in the HPISDataMa…
- CVE-2007-5605Buffer overflow in the GetFileTime function in the HPISDataM…
- CVE-2007-5606Buffer overflow in the MoveFile function in the HPISDataMana…
- CVE-2007-5607Buffer overflow in the RegistryString function in the HPISDa…
- CVE-2007-5610The DeleteSingleFile function in the HPISDataManagerLib.Data…
- CVE-2007-5612CIM Server in IBM Director 5.20.1 and earlier allows remote …
- CVE-2007-5613Cross-site scripting (XSS) vulnerability in Dump Servlet in …
- CVE-2007-5614Mortbay Jetty before 6.1.6rc1 does not properly handle "cert…
- CVE-2007-5615CRLF injection vulnerability in Mortbay Jetty before 6.1.6rc…
- CVE-2007-5616ssh-signer in SSH Tectia Client and Server 5.x before 5.2.4,…
Are you affected by CVE-2007-5608?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
