Remote File Creation Vulnerability in HP Instant Support ActiveX Control
CVE-2008-0952
Currently unrated
What is CVE-2008-0952?
A vulnerability exists in the AppendStringToFile function within the HPISDataManagerLib.Datamgr ActiveX control in HP Instant Support versions prior to 1.0.0.24. This flaw enables remote attackers to generate files containing arbitrary content on the affected system by manipulating the full pathname and content through crafted parameters. This can lead to unauthorized file creation, impacting the integrity and confidentiality of system data.