Vulnerabilities > CVE-2015-6857 - Unspecified vulnerability in HP Loadrunner and Performance Center
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN hp
nessus
Summary
Unspecified vulnerability in Virtual Table Server (VTS) in HP LoadRunner 11.52, 12.00, 12.01, 12.02, and 12.50 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-3138.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 10 |
Nessus
NASL family Gain a shell remotely NASL id HP_VTS_IMPORT_DB_RCE.NASL description The HP Virtual Table Server running on the remote host is affected by a remote code execution vulnerability. An unauthenticated, remote attacker can exploit this, via a malicious connection string or SQL command, to execute arbitrary code. last seen 2020-06-01 modified 2020-06-02 plugin id 88021 published 2016-01-20 reporter This script is Copyright (C) 2016-2019 and is owned by Tenable, Inc. or an Affiliate thereof. source https://www.tenable.com/plugins/nessus/88021 title HP Virtual Table Server (VTS) Database Import RCE NASL family Windows NASL id HP_LOADRUNNER_VTS_RCE.NASL description The version of HP LoadRunner installed on the remote host is 11.52, 12.00, 12.01, 12.02, or 12.50. It is, therefore, affected by a remote code execution vulnerability in the Virtual Table Server (VTS). An unauthenticated, remote attacker can exploit this, via a malicious connection string or SQL command, to execute arbitrary code. last seen 2020-06-01 modified 2020-06-02 plugin id 87211 published 2015-12-05 reporter This script is Copyright (C) 2015-2019 and is owned by Tenable, Inc. or an Affiliate thereof. source https://www.tenable.com/plugins/nessus/87211 title HP LoadRunner 11.52 / 12.00 / 12.01 / 12.02 / 12.50 Virtual Table Server RCE
References
- http://www.securityfocus.com/bid/77946
- http://www.securityfocus.com/bid/77946
- http://www.securitytracker.com/id/1034259
- http://www.securitytracker.com/id/1034259
- http://www.zerodayinitiative.com/advisories/ZDI-15-581
- http://www.zerodayinitiative.com/advisories/ZDI-15-581
- https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04900820
- https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04900820
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04907374
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04907374