CVE-2009-3693: Path Traversal
Directory traversal vulnerability in the Persits.XUpload.2 ActiveX control (XUpload.ocx) in HP LoadRunner 9.5 allows remote attackers to create arbitrary files via \.. (backwards slash dot dot) sequences in the third argument to the MakeHttpRequest method.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-3693?
CVE-2009-3693 is classified as a high severity vulnerability due to its potential for remote exploitation.
How do I fix CVE-2009-3693?
To fix CVE-2009-3693, update to a patched version of the Persits.XUpload.2 ActiveX control or HP LoadRunner that addresses this vulnerability.
What systems are affected by CVE-2009-3693?
CVE-2009-3693 affects the Persits.XUpload.2 ActiveX control version 2.0 and HP LoadRunner version 9.5.
What type of attack can exploit CVE-2009-3693?
CVE-2009-3693 can be exploited via directory traversal attacks, allowing remote attackers to create arbitrary files on the server.
When was CVE-2009-3693 disclosed?
CVE-2009-3693 was disclosed in December 2009.