File Download Vulnerability in HP Instant Support by HP
CVE-2007-5608
Currently unrated
Summary
The DownloadFile function in the HPISDataManagerLib.Datamgr ActiveX control present in HPISDataManager.dll prior to version 1.0.0.24 allows attackers to initiate unintended file downloads on client systems. By crafting a specific URL in the first argument and providing a destination filename in the second, malicious entities can exploit this vulnerability for unauthorized file transfers to client machines, potentially leading to further security breaches.
References
Timeline
Vulnerability published
Vulnerability Reserved