CVE-2007-6513
published 2007-12-21CVE-2007-6513: HP eSupportDiagnostics ActiveX control (hpediag.dll) 1.0.11.0 exports dangerous methods, which allows remote attackers to (1) read arbitrary files via the…
PriorityP426medium4.3CVSS 2.0
AVNACMAuNCPINAN
EXPLOIT
EPSS
2.32%
81.3th percentile
HP eSupportDiagnostics ActiveX control (hpediag.dll) 1.0.11.0 exports dangerous methods, which allows remote attackers to (1) read arbitrary files via the ReadTextFile method, or (2) read arbitrary registry values via the ReadValue method.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| hp | esupportdiagnostics | — | — |
| hp | software_update | <= 4.000.009.002 | — |
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-229w-w68g-gcf2: HP eSupportDiagnostics ActiveX control (hpediag
ghsa_unreviewed·2022-05-01
CVE-2007-6513 [MEDIUM] CWE-200 GHSA-229w-w68g-gcf2: HP eSupportDiagnostics ActiveX control (hpediag
HP eSupportDiagnostics ActiveX control (hpediag.dll) 1.0.11.0 exports dangerous methods, which allows remote attackers to (1) read arbitrary files via the ReadTextFile method, or (2) read arbitrary registry values via the ReadValue method.
GHSA
GHSA-f3cg-58h9-xv3v: Unspecified vulnerability in the HP HPeDiag (aka eSupportDiagnostics) ActiveX control in hpediag
ghsa_unreviewed·2022-05-01·CVSS 4.3
CVE-2008-0712 [MEDIUM] GHSA-f3cg-58h9-xv3v: Unspecified vulnerability in the HP HPeDiag (aka eSupportDiagnostics) ActiveX control in hpediag
Unspecified vulnerability in the HP HPeDiag (aka eSupportDiagnostics) ActiveX control in hpediag.dll in HP Software Update 4.000.009.002 and earlier allows remote attackers to execute arbitrary code or obtain sensitive information via unspecified vectors. NOTE: this might overlap CVE-2007-6513.
No detection rules found.
No writeups or analysis indexed.
http://archives.neohapsis.com/archives/fulldisclosure/2007-12/0470.htmlhttp://www.heise-security.co.uk/news/100934http://www.securityfocus.com/bid/26967https://exchange.xforce.ibmcloud.com/vulnerabilities/39156http://archives.neohapsis.com/archives/fulldisclosure/2007-12/0470.htmlhttp://www.heise-security.co.uk/news/100934http://www.securityfocus.com/bid/26967https://exchange.xforce.ibmcloud.com/vulnerabilities/39156
2007-12-21
Published