First published: Wed Jun 04 2008(Updated: )
The AppendStringToFile function in the HPISDataManagerLib.Datamgr ActiveX control in HPISDataManager.dll in HP Instant Support before 1.0.0.24 allows remote attackers to create files with arbitrary content via a full pathname in the first argument and the content in the second argument, a different vulnerability than CVE-2007-5608 and CVE-2008-0953.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
HP Instant Support | <=1.0.0.23 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-0952 is considered a critical vulnerability due to its potential to allow remote attackers to create arbitrary files.
To mitigate CVE-2008-0952, you should upgrade HP Instant Support to version 1.0.0.24 or later.
CVE-2008-0952 affects HP Instant Support versions prior to 1.0.0.24.
CVE-2008-0952 can be exploited through remote code execution or arbitrary file creation attacks.
There is no official workaround for CVE-2008-0952; updating to the latest version is recommended.