File Download Vulnerability in HP Instant Support by HP
CVE-2007-5608

Currently unrated

Key Information:

Vendor
HP
Vendor
CVE Published:
4 June 2008

Summary

The DownloadFile function in the HPISDataManagerLib.Datamgr ActiveX control present in HPISDataManager.dll prior to version 1.0.0.24 allows attackers to initiate unintended file downloads on client systems. By crafting a specific URL in the first argument and providing a destination filename in the second, malicious entities can exploit this vulnerability for unauthorized file transfers to client machines, potentially leading to further security breaches.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.