Vulnerabilities > CVE-2007-1882 - SQL-Injection vulnerability in HP Mercury Quality Center 9.0
Attack vector
NETWORK Attack complexity
LOW Privileges required
SINGLE Confidentiality impact
PARTIAL Integrity impact
PARTIAL Availability impact
PARTIAL Summary
qcbin/servlet/tdservlet/TDAPI_GeneralWebTreatment in HP Mercury Quality Center 9.0 build 9.1.0.4352 allows remote authenticated users to execute arbitrary SQL commands via the RunQuery method.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description | HP Mercury Quality Center 9.0 build 9.1.0.4352 SQL Execution Exploit. CVE-2007-1882. Remote exploits for multiple platform |
id | EDB-ID:3654 |
last seen | 2016-01-31 |
modified | 2007-04-03 |
published | 2007-04-03 |
reporter | Isma Khan |
source | https://www.exploit-db.com/download/3654/ |
title | HP Mercury Quality Center 9.0 build 9.1.0.4352 SQL Execution Exploit |
References
- http://lists.grok.org.uk/pipermail/full-disclosure/2007-April/053406.html
- http://osvdb.org/34630
- http://secunia.com/advisories/24730
- http://securityreason.com/securityalert/2527
- http://www.securitytracker.com/id?1017842
- http://www.vupen.com/english/advisories/2007/1246
- https://exchange.xforce.ibmcloud.com/vulnerabilities/33385