CVE-2008-0952: Critical severity hp instant support vulnerability
The AppendStringToFile function in the HPISDataManagerLib.Datamgr ActiveX control in HPISDataManager.dll in HP Instant Support before 1.0.0.24 allows remote attackers to create files with arbitrary content via a full pathname in the first argument and the content in the second argument, a different vulnerability than CVE-2007-5608 and CVE-2008-0953.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-0952?
CVE-2008-0952 is considered a critical vulnerability due to its potential to allow remote attackers to create arbitrary files.
How do I fix CVE-2008-0952?
To mitigate CVE-2008-0952, you should upgrade HP Instant Support to version 1.0.0.24 or later.
What software is affected by CVE-2008-0952?
CVE-2008-0952 affects HP Instant Support versions prior to 1.0.0.24.
What type of attack can exploit CVE-2008-0952?
CVE-2008-0952 can be exploited through remote code execution or arbitrary file creation attacks.
Is there a workaround for CVE-2008-0952?
There is no official workaround for CVE-2008-0952; updating to the latest version is recommended.