Vulnerabilities > CVE-2007-1882 - SQL-Injection vulnerability in HP Mercury Quality Center 9.0

047910
CVSS 6.5 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
SINGLE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
hp
exploit available

Summary

qcbin/servlet/tdservlet/TDAPI_GeneralWebTreatment in HP Mercury Quality Center 9.0 build 9.1.0.4352 allows remote authenticated users to execute arbitrary SQL commands via the RunQuery method.

Vulnerable Configurations

Part Description Count
Application
Hp
1

Exploit-Db

descriptionHP Mercury Quality Center 9.0 build 9.1.0.4352 SQL Execution Exploit. CVE-2007-1882. Remote exploits for multiple platform
idEDB-ID:3654
last seen2016-01-31
modified2007-04-03
published2007-04-03
reporterIsma Khan
sourcehttps://www.exploit-db.com/download/3654/
titleHP Mercury Quality Center 9.0 build 9.1.0.4352 SQL Execution Exploit